Source: | Binary string: api-ms-win-crt-runtime-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\TextExtractor.pdb444 source: alg.exe, 0000000D.00000003.1687730891.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\TextExtractor.pdb source: alg.exe, 0000000D.00000003.1687730891.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\jjs_objs\jjs.pdb source: jjs.exe.13.dr |
Source: | Binary string: mavinject32.pdbGCTL source: alg.exe, 0000000D.00000003.1873376292.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1876347240.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PresentationFontCache.pdb source: alg.exe, 0000000D.00000003.1602398119.00000000016C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-file-l1-2-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-debug-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\setup.exe.pdbOGP source: setup.exe1.13.dr |
Source: | Binary string: api-ms-win-core-sysinfo-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-filesystem-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: plugin-container.pdb source: alg.exe, 0000000D.00000003.2202633741.0000000000650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WebInstaller\AcroMiniServicesUpdater.pdb source: alg.exe, 0000000D.00000003.1637621243.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x64\ship\click2run\x-none\InspectorOfficeGadget.pdb source: alg.exe, 0000000D.00000003.1863510269.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ShowAppPickerForPDF\Release_x64\ShowAppPickerForPDF.pdb source: alg.exe, 0000000D.00000003.1812452407.0000000001450000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1806949825.0000000001660000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-heap-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp, api-ms-win-core-heap-l1-1-0.dll.8.dr |
Source: | Binary string: d:\dbs\el\omr\target\x86\ship\dcf\x-none\Common.ShowHelp.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: Common.ShowHelp.exe.13.dr |
Source: | Binary string: Microsoft.VisualBasic.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: vcruntime140.i386.pdbGCTL source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-environment-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: pingsender.pdb source: alg.exe, 0000000D.00000003.2182345698.0000000000650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\mozglue\build\mozglue.pdb11 source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-processthreads-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-console-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-private-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.ni.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb)) source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msvcp140.i386.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-profile-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: maintenanceservice.pdb source: alg.exe, 0000000D.00000003.2131240760.0000000000440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\setup.exe.pdb source: setup.exe1.13.dr |
Source: | Binary string: firefox.pdb source: alg.exe, 0000000D.00000003.2112410522.0000000000430000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x64\ship\click2run\x-none\InspectorOfficeGadget.pdbY source: alg.exe, 0000000D.00000003.1863510269.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-time-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: firefox.pdbP source: alg.exe, 0000000D.00000003.2112410522.0000000000430000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WCChromeNativeMessagingHost.pdb source: alg.exe, 0000000D.00000003.1724231457.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-handle-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\workspace\CR-Windows-x64-Client-Builder\x64\Release\CRWindowsClientService.pdb source: alg.exe, 0000000D.00000003.1742573812.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\b\s\w\ir\cache\builder\src\out\Release_x64\chrome_pwa_launcher.exe.pdb source: alg.exe, 0000000D.00000003.1947973037.0000000001480000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-synch-l1-2-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ShowAppPickerForPDF\Release_x64\ShowAppPickerForPDF.pdb$$ source: alg.exe, 0000000D.00000003.1812452407.0000000001450000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1806949825.0000000001660000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-processenvironment-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Windows.Forms.pdb.> source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: mscorlib.ni.pdbRSDS source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-core-localization-l1-2-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Configuration.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\deploy\tmp\ssvagent\obj\ssvagent.pdb source: ssvagent.exe.13.dr |
Source: | Binary string: minidump-analyzer.pdb source: alg.exe, 0000000D.00000003.2157918575.0000000000650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-processthreads-l1-1-1.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-namedpipe-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-multibyte-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp, api-ms-win-crt-multibyte-l1-1-0.dll.8.dr |
Source: | Binary string: api-ms-win-core-rtlsupport-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msvcp140.i386.pdbGCTL source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-crt-process-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Drawing.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.pdb4 source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-core-interlocked-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release\Plug_ins\pi_brokers\32BitMAPIBroker.pdb source: alg.exe, 0000000D.00000003.1774099876.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-heap-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: AppVShNotify.pdbGCTL source: alg.exe, 0000000D.00000003.1859682808.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-string-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\work\p4\splinters\Splinters\S\BuildResults\bin\Win32\ReaderRelease\FullTrustNotifier\FullTrustNotifier.pdb77.GCTL source: alg.exe, 0000000D.00000003.1794989425.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-locale-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\PkgInstaller\base\ntsetup\SrvPack.Main\tools\sfxcab\sfxcab\objfre\i386\sfxcab.pdb source: alg.exe, 0000000D.00000003.1838763806.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1839825345.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1846357220.0000000001530000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\mozglue\build\mozglue.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Accessibility.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: ADelRCP_Exec.pdb source: alg.exe, 0000000D.00000003.1696706041.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss3.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-memory-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\freebl\freebl_freebl3\freebl3.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: crashreporter.pdb source: alg.exe, 0000000D.00000003.2059367986.0000000000400000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\plug_ins\pi_brokers\MSRMSPIBroker.pdbAAAGCTL source: alg.exe, 0000000D.00000003.1790232245.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-stdio-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WCChromeNativeMessagingHost.pdb888 source: alg.exe, 0000000D.00000003.1724231457.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Xml.ni.pdbRSDS# source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.Core.ni.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-core-util-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: locator.pdb source: Locator.exe.8.dr |
Source: | Binary string: api-ms-win-core-synch-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-errorhandling-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ADelRCP_Exec.pdbCC9 source: alg.exe, 0000000D.00000003.1696706041.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\freebl\freebl_freebl3\freebl3.pdbZZ source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-file-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: private_browsing.pdb source: alg.exe, 0000000D.00000003.2212108302.0000000000670000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-convert-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\PkgInstaller\base\ntsetup\SrvPack.Main\tools\sfxcab\sfxcab\objfre\i386\sfxcab.pdbU source: alg.exe, 0000000D.00000003.1838763806.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1839825345.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1846357220.0000000001530000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WebInstaller\AcroMiniServicesUpdater.pdbT source: alg.exe, 0000000D.00000003.1637621243.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\workspace\CR-Windows-x64-Client-Builder\x64\Release\CRWindowsClientService.pdbGG source: alg.exe, 0000000D.00000003.1742573812.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\jjs_objs\jjs.pdb source: jjs.exe.13.dr |
Source: | Binary string: ucrtbase.pdbUGP source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mavinject32.pdb source: alg.exe, 0000000D.00000003.1873376292.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1876347240.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: pixuBt.pdb source: MUH030425.exe, WER4A31.tmp.dmp.18.dr |
Source: | Binary string: 64BitMAPIBroker.pdb source: alg.exe, 0000000D.00000003.1781474310.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Configuration.ni.pdbRSDScUN source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: d:\dbs\el\omr\target\x86\ship\dcf\x-none\Common.ShowHelp.pdb source: Common.ShowHelp.exe.13.dr |
Source: | Binary string: System.Drawing.pdb( source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: E:\jenkins\workspace\NGL_WORKFLOW\build\master\win64\Release\Acrobat\project\win\ngl-workflow\x64\Release (Acrobat)\adobe_licensing_wf_helper_acro.pdb source: alg.exe, 0000000D.00000003.1770420067.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\softoken\legacydb\legacydb_nssdbm3\nssdbm3.pdb-- source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: private_browsing.pdbp source: alg.exe, 0000000D.00000003.2212108302.0000000000670000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\work\p4\splinters\Splinters\S\BuildResults\bin\Win32\ReaderRelease\FullTrustNotifier\FullTrustNotifier.pdb source: alg.exe, 0000000D.00000003.1794989425.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release\Plug_ins\pi_brokers\32BitMAPIBroker.pdb@@ source: alg.exe, 0000000D.00000003.1774099876.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Xml.ni.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.ni.pdbRSDS source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\plug_ins\pi_brokers\MSRMSPIBroker.pdb source: alg.exe, 0000000D.00000003.1790232245.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: maintenanceservice.pdb` source: alg.exe, 0000000D.00000003.2131240760.0000000000440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Accessibility.pdbD(L source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\Eula.pdb source: alg.exe, 0000000D.00000003.1747818920.0000000001650000.00000004.00001000.00020000.00000000.sdmp, Eula.exe.13.dr |
Source: | Binary string: System.Configuration.ni.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-core-datetime-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-conio-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\deploy\tmp\ssvagent\obj\ssvagent.pdb<<7 source: ssvagent.exe.13.dr |
Source: | Binary string: api-ms-win-crt-math-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Xml.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: vcruntime140.i386.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-utility-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Windows.Forms.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\softoken\legacydb\legacydb_nssdbm3\nssdbm3.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-timezone-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: pixuBt.pdbSHA256 source: MUH030425.exe, WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-core-string-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PresentationFontCache.pdbHt^t Pt_CorExeMainmscoree.dll source: alg.exe, 0000000D.00000003.1602398119.00000000016C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-file-l2-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: locator.pdbGCTL source: Locator.exe.8.dr |
Source: | Binary string: api-ms-win-core-libraryloader-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Core.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: default-browser-agent.pdb source: alg.exe, 0000000D.00000003.2095519854.0000000000400000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: updater.pdb source: alg.exe, 0000000D.00000003.2233883361.0000000000650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: AppVShNotify.pdb source: alg.exe, 0000000D.00000003.1859682808.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\Eula.pdb888 source: alg.exe, 0000000D.00000003.1747818920.0000000001650000.00000004.00001000.00020000.00000000.sdmp, Eula.exe.13.dr |
Source: | Binary string: System.Xml.pdb@\ source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.ni.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.Core.ni.pdbRSDS source: WER4A31.tmp.dmp.18.dr |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\pingsender.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\vds.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\snmptrap.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\Spectrum.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Windows Media Player\wmpnetwk.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\Locator.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\7-Zip\7z.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.134\Installer\chrmstp.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\AppVClient.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\crashreporter.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\SysWOW64\perfhost.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\7-Zip\7zG.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\msiexec.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.134\Installer\setup.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\TieringEngineService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\firefox.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\updater.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\7-Zip\Uninstall.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\FXSSVC.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.134\elevation_service.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\SensorDataService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\msdtc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\wbem\WmiApSrv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\alg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\7-Zip\7zFM.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.134\notification_helper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\wbengine.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\VSSVC.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\SearchIndexer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\private_browsing.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\Install\{9DD40E31-8782-438B-BCFD-713DE1B3090F}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.134\chrome_pwa_launcher.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\AgentService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\OpenSSH\ssh-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\plugin-container.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | |
Source: global traffic | HTTP traffic detected: POST /TP341/index.php HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)Host: k1d5.icuContent-Length: 101Cache-Control: no-cacheData Raw: 00 00 00 45 14 8b 30 62 ef 26 66 9a 26 66 9a 46 70 9d 35 70 9c 47 70 9d 3a 70 9d 37 70 9d 32 70 9d 37 70 9d 3a 70 9d 33 70 9d 34 14 8b 31 11 8b 30 6c ea 26 66 97 46 14 e8 40 10 8b 31 11 8b 30 66 ef 47 11 8b 30 65 8b 30 63 8b 30 65 8b 30 60 8b 31 11 8b 30 66 e8 26 66 99 26 66 98 26 66 9a 46 70 9d 3b 17 Data Ascii: E0b&f&fFp5pGp:p7p2p7p:p3p410l&fF@10fG0e0c0e0`10f&f&f&fFp; |
Source: global traffic | HTTP traffic detected: POST /pj HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: pywolwnvd.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 842 |
Source: global traffic | HTTP traffic detected: POST /pipasemmaulffaco HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ssbzmoy.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 842 |
Source: global traffic | HTTP traffic detected: POST /iqhmiklhuwbcg HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: pywolwnvd.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /jwaobwjsxgqjxsn HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: cvgrf.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 842 |
Source: global traffic | HTTP traffic detected: POST /krqescexcxjlmqje HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ssbzmoy.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /jakwogupdhlp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: npukfztj.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 842 |
Source: global traffic | HTTP traffic detected: POST /fmwgjkn HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: cvgrf.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /cygwkoswoy HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: przvgke.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 842 |
Source: global traffic | HTTP traffic detected: GET /cygwkoswoy?usid=18&utid=30152678086 HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Host: ww12.przvgke.biz |
Source: global traffic | HTTP traffic detected: POST /exyejkfqn HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: npukfztj.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /b HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: przvgke.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 842 |
Source: global traffic | HTTP traffic detected: POST /gedtsq HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: przvgke.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: GET /b?usid=18&utid=30152678348 HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Host: ww7.przvgke.biz |
Source: global traffic | HTTP traffic detected: POST /TP341/index.php HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)Host: k1d5.icuContent-Length: 42988Cache-Control: no-cache |
Source: global traffic | HTTP traffic detected: POST /iqbvkcsnipxly HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: knjghuig.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 842 |
Source: global traffic | HTTP traffic detected: GET /gedtsq?usid=18&utid=30152678479 HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Host: ww12.przvgke.biz |
Source: global traffic | HTTP traffic detected: POST /en HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: przvgke.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: GET /en?usid=18&utid=30152678739 HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Host: ww7.przvgke.biz |
Source: global traffic | HTTP traffic detected: POST /wt HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: lpuegx.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 842 |
Source: global traffic | HTTP traffic detected: POST /xfhngbevi HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: knjghuig.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /aopfhnckuovs HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: lpuegx.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /reeuv HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: lpuegx.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /fkj HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: vjaxhpbji.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /mtrjsdrytjxvslm HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: vjaxhpbji.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /dnmpvtql HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: xlfhhhm.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /lljqple HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ifsaia.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /yxchsqwoy HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: saytjshyf.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /eyajoanbw HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: vcddkls.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /wgmealrwqlbauh HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: vcddkls.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /yhikx HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: fwiwk.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: GET /yhikx?usid=18&utid=30152687280 HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Host: ww7.fwiwk.biz |
Source: global traffic | HTTP traffic detected: POST /xrkixnpk HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: fwiwk.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: GET /xrkixnpk?usid=18&utid=30152687444 HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Host: ww12.fwiwk.biz |
Source: global traffic | HTTP traffic detected: POST /rrvggovttpevpbe HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: tbjrpv.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /ljnlowt HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: deoci.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /ayiycmrfnan HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: gytujflc.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /kqipv HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: gytujflc.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /tpyri HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: qaynky.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /kkcqqeuyeyu HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: bumxkqgxu.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /vipn HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: dwrqljrr.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /xtqnbvhp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: nqwjmb.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /if HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ytctnunms.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /seueafvlbcmx HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: myups.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /vqrfhgg HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: myups.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /jqlotfcyykbfgsp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: oshhkdluh.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /cuxawpwbnkhn HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: yunalwv.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /jttp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: yunalwv.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /wpnrqhmpnuisgi HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: jpskm.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /xhfpy HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: lrxdmhrr.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /llkyp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: wllvnzb.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /j HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: gnqgo.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /edke HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: jhvzpcfg.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /gtvq HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: acwjcqqv.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /kfeqymn HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: vyome.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /kih HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: yauexmxk.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /kgihcqktxx HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: iuzpxe.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /gd HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: sxmiywsfv.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /op HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: vrrazpdh.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /aywxxumeinieee HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ftxlah.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /ksbp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: typgfhb.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /shrlpi HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: esuzf.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /mgwvuleuoxgka HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: gvijgjwkh.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /v HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: qpnczch.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /taq HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: brsua.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /bwq HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: dlynankz.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /rgpseg HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: dlynankz.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /fkkyxxyvwxtnw HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: oflybfv.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /muicwswwpsvuoaa HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: yhqqc.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /b HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: yhqqc.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /obax HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: mnjmhp.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /vspbg HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: opowhhece.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /smhxeb HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: jdhhbs.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /cmutmcflogtu HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: jdhhbs.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /jfsimcxiyb HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: mgmsclkyu.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /iuxqrsqameemay HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: warkcdu.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /l HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: gcedd.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /btxiqnehclrfsqon HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: jwkoeoqns.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /nbbgwwsoahqctkx HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: xccjj.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /mbhdlepkeeimc HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: hehckyov.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /osobbhwa HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: rynmcq.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /vcdqqdvbwhgvsi HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: rynmcq.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /oajmbd HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: uaafd.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /k HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: eufxebus.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /gbcstiuy HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: pwlqfu.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /rt HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: rrqafepng.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /inonlcbojnu HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ctdtgwag.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /waxb HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: tnevuluw.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /icxil HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: whjovd.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /rkcyrfbj HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: whjovd.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /decjayv HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: gjogvvpsf.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /oflvinlq HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: gjogvvpsf.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /cctwfdagfuqgkcrp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: reczwga.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /fysbuxlbm HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: bghjpy.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /wfyiibhukdwvo HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: bghjpy.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /rkobxpllgfpahuau HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: damcprvgv.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /ej HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ocsvqjg.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /pimlqcf HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ywffr.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /yxqtpqinac HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ecxbwt.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /lakonfsatp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: pectx.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /prs HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: zyiexezl.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /wnmeou HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: banwyw.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /xg HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: wxgzshna.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: GET /xg?usid=18&utid=30152701801 HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Host: ww1.wxgzshna.biz |
Source: global traffic | HTTP traffic detected: POST /blqtjaa HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: zrlssa.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /shntjujahohucfd HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: jlqltsjvh.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: global traffic | HTTP traffic detected: POST /gsucnqsvdim HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: jlqltsjvh.bizUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 MicroMessenger/6.5.2.501 NetType/WIFI WindowsWechat QBCore/3.43.884.400 QQBrowser/9.0.2524.400Content-Length: 778 |
Source: alg.exe, 0000000D.00000003.2181291982.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2259482527.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2288608476.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2276640960.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2200527185.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2267339346.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2229080820.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2246556685.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2210269453.000000000053A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150/kgihcqktxx |
Source: alg.exe, 0000000D.00000003.2259482527.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2246556685.000000000053A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150/ksbp |
Source: alg.exe, 0000000D.00000003.1913930438.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1944474303.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1914915915.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1957228645.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1907846105.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1972777177.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1908959853.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1955019744.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1932675425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1917871727.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1907606835.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1966658212.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150/lljqple |
Source: alg.exe, 0000000D.00000003.1907846105.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150/lljqple0b1d |
Source: alg.exe, 0000000D.00000003.1913930438.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1944474303.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1914915915.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1957228645.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1972777177.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1908959853.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1955019744.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1932675425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1917871727.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1907606835.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1966658212.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150/lljqplest.exe |
Source: alg.exe, 0000000D.00000003.2025611759.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032480249.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2040378345.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007443563.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2000758926.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007952814.0000000000538000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2017070889.0000000000538000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032923896.0000000000538000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2016629204.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150/tpyri7444 |
Source: alg.exe, 0000000D.00000003.1917967381.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1914053502.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1932808513.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1907846105.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1955254799.0000000000509000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1944621326.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150:80/lljqple |
Source: alg.exe, 0000000D.00000003.2046169214.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2116238505.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2088717654.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2040810220.0000000000509000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2056093276.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2078285049.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://165.160.13.20/seueafvlbcmx |
Source: alg.exe, 0000000D.00000003.2041235754.0000000000557000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://165.160.13.20/seueafvlbcmxpbe |
Source: alg.exe, 0000000D.00000003.2046169214.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2046971759.000000000050E000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2064037327.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2056093276.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://165.160.13.20/vqrfhgg |
Source: alg.exe, 0000000D.00000003.2067214816.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2046169214.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2056093276.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://165.160.13.20/vqrfhggc |
Source: alg.exe, 0000000D.00000003.2046971759.000000000050E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://165.160.13.20/vqrfhggs |
Source: alg.exe, 0000000D.00000003.2040810220.0000000000509000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://165.160.13.20:80/seueafvlbcmx |
Source: alg.exe, 0000000D.00000003.1917967381.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1932808513.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/eyajoanbw |
Source: alg.exe, 0000000D.00000003.1944474303.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1957228645.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1972777177.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1955019744.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1932675425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1917871727.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1966658212.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/eyajoanbw.exe |
Source: alg.exe, 0000000D.00000003.1932675425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1917871727.000000000052C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/eyajoanbwM |
Source: alg.exe, 0000000D.00000003.2181291982.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2163395398.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2154720665.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2143416467.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2144486551.0000000000539000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/gtvqg |
Source: alg.exe, 0000000D.00000003.2106093399.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2116238505.000000000053A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/llkyp |
Source: alg.exe, 0000000D.00000003.1944474303.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1932675425.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/wgmealrwqlbauh |
Source: alg.exe, 0000000D.00000003.1957847112.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1966658212.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1932292743.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1983866160.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1973326884.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1943728081.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2000758926.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1999368202.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1955019744.0000000000557000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/wgmealrwqlbauhTf |
Source: alg.exe, 0000000D.00000003.1572794877.0000000000532000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1576172278.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1576253777.000000000052F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1575202487.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1576298008.000000000050E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/xfhngbevi |
Source: alg.exe, 0000000D.00000003.1575202487.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/xfhngbevi2$d |
Source: alg.exe, 0000000D.00000003.1917967381.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1932808513.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107:80/eyajoanbw |
Source: alg.exe, 0000000D.00000003.1508234940.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107:80/krqescexcxjlmqje |
Source: alg.exe, 0000000D.00000003.1790797442.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1575202487.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107:80/xfhngbevi |
Source: alg.exe, 0000000D.00000003.2153120949.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.246.231.120/kfeqymn |
Source: alg.exe, 0000000D.00000003.2210269453.000000000053A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.246.231.120/opP |
Source: alg.exe, 0000000D.00000003.2259482527.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2276640960.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2267339346.000000000053A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.246.231.120/shrlpi |
Source: alg.exe, 0000000D.00000003.2257351195.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.246.231.120/shrlpiinieee |
Source: alg.exe, 0000000D.00000003.2179969488.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2257351195.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2227343739.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2276640960.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2210269453.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2266240425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2197748874.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2106093399.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2080646306.000000000050F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2161214560.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2288608476.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2245066266.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2143416467.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2116238505.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2088717654.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2078285049.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2153120949.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2124390441.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.246.231.120/wpnrqhmpnuisgi |
Source: alg.exe, 0000000D.00000003.2068786844.0000000000565000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/ |
Source: alg.exe, 0000000D.00000003.2016629204.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2046169214.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007443563.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2026221908.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2041235754.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032480249.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2078285049.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1983866160.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2000758926.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2067214816.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1999368202.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2056093276.0000000000557000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/ayiycmrfnan |
Source: alg.exe, 0000000D.00000003.2025611759.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007443563.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1999368202.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1983866160.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2016629204.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/ayiycmrfnan- |
Source: alg.exe, 0000000D.00000003.2067214816.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2065019404.000000000050F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2106093399.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2116238505.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2088717654.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2078285049.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2124390441.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/cuxawpwbnkhn |
Source: alg.exe, 0000000D.00000003.2062612258.000000000052A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/cuxawpwbnkhnM |
Source: alg.exe, 0000000D.00000003.2179969488.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2067214816.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2257351195.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2227343739.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2276640960.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2210269453.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2266240425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2197748874.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2106093399.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2161214560.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2288608476.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2245066266.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2143416467.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2116238505.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2088717654.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2078285049.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2153120949.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2124390441.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/cuxawpwbnkhnU |
Source: alg.exe, 0000000D.00000003.2065019404.000000000050F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/cuxawpwbnkhns#$u |
Source: alg.exe, 0000000D.00000003.2069852108.000000000050F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/jttp |
Source: alg.exe, 0000000D.00000003.2089955706.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2067214816.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2079601241.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2125759526.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2106093399.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2116238505.000000000053A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/jttpg |
Source: alg.exe, 0000000D.00000003.1983866160.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007443563.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2000758926.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007952814.0000000000538000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/kqipv( |
Source: alg.exe, 0000000D.00000003.2276640960.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2266240425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2288608476.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.94.10.34/mgwvuleuoxgka |
Source: alg.exe, 0000000D.00000003.2288608476.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2276640960.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2267339346.000000000053A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.94.10.34/mgwvuleuoxgkaL |
Source: alg.exe, 0000000D.00000003.2276640960.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2266240425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2288608476.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.94.10.34/mgwvuleuoxgkarue |
Source: alg.exe, 0000000D.00000003.2040810220.0000000000509000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.94.10.34:80/if8 |
Source: alg.exe, 0000000D.00000003.1972777177.0000000000539000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.227.7.138/ljnlowtt |
Source: alg.exe, 0000000D.00000003.2040810220.0000000000509000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.227.7.138:80/ljnlowt |
Source: alg.exe, 0000000D.00000003.1966658212.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1983866160.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1973326884.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2000758926.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1999368202.0000000000557000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.246.200.160/rrvggovttpevpbe |
Source: alg.exe, 0000000D.00000003.2025611759.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://35.164.78.200/xtqnbvhp |
Source: alg.exe, 0000000D.00000003.2025611759.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032480249.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032923896.0000000000538000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://35.164.78.200/xtqnbvhpX |
Source: alg.exe, 0000000D.00000003.2125759526.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2143416467.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2144486551.0000000000539000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.221.84.105/edke |
Source: alg.exe, 0000000D.00000003.2067214816.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2025611759.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032480249.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007443563.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2040378345.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2046169214.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2016629204.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2056093276.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2078285049.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.221.84.105/kkcqqeuyeyu |
Source: alg.exe, 0000000D.00000003.2016629204.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2046169214.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007443563.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2026221908.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2041235754.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032480249.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.0000000000557000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2056093276.0000000000557000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.221.84.105/kkcqqeuyeyuuhTf |
Source: alg.exe, 0000000D.00000003.1914053502.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1914915915.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1917871727.000000000052C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.221.84.105/yxchsqwoy |
Source: alg.exe, 0000000D.00000003.1529626183.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.221.84.105:80/exyejkfqnn: |
Source: alg.exe, 0000000D.00000003.1917967381.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1914053502.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.221.84.105:80/yxchsqwoyP |
Source: alg.exe, 0000000D.00000003.1893684140.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1892475238.000000000052C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://47.129.31.212/ |
Source: alg.exe, 0000000D.00000003.2227343739.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://47.129.31.212/aywxxumeinieee |
Source: alg.exe, 0000000D.00000003.2257351195.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2227343739.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2276640960.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2266240425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2288608476.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2245066266.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://47.129.31.212/aywxxumeinieee- |
Source: alg.exe, 0000000D.00000003.2257351195.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2227343739.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2266240425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2245066266.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://47.129.31.212/aywxxumeinieeeJ |
Source: alg.exe, 0000000D.00000003.1892475238.000000000052C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://47.129.31.212/dnmpvtql |
Source: alg.exe, 0000000D.00000003.1892690377.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://47.129.31.212:80/dnmpvtql |
Source: alg.exe, 0000000D.00000003.1492313549.00000000004ED000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177/ |
Source: alg.exe, 0000000D.00000003.1492313549.00000000004ED000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177/T |
Source: alg.exe, 0000000D.00000003.1489265743.000000000050C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1493620638.0000000000509000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1492313549.00000000004ED000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177/iqhmiklhuwbcg |
Source: alg.exe, 0000000D.00000003.2179969488.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2067214816.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2257351195.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2227343739.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2276640960.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2210269453.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2266240425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2197748874.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2106093399.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2161214560.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2288608476.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2245066266.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2143416467.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2116238505.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2088717654.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2056093276.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2078285049.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2153120949.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2124390441.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177/jqlotfcyykbfgsp |
Source: alg.exe, 0000000D.00000003.1492313549.00000000004ED000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177/p |
Source: alg.exe, 0000000D.00000003.1492313549.00000000004ED000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177/t |
Source: alg.exe, 0000000D.00000003.2017070889.0000000000538000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2016629204.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177/vipn( |
Source: alg.exe, 0000000D.00000003.2090939732.000000000050F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2108245828.000000000050F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177/xhfpy |
Source: alg.exe, 0000000D.00000003.2090939732.000000000050F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2108245828.000000000050F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177/xhfpybfgsp7$a |
Source: alg.exe, 0000000D.00000003.2089955706.000000000053A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177/xhfpyt |
Source: alg.exe, 0000000D.00000003.1521291058.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://54.244.188.177:80/fmwgjknn: |
Source: alg.exe, 0000000D.00000003.1955254799.0000000000509000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/xrkixnpk |
Source: alg.exe, 0000000D.00000003.1999368202.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1957228645.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1972777177.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1955019744.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1983866160.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1966658212.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/xrkixnpkc |
Source: alg.exe, 0000000D.00000003.1957228645.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1955019744.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1966658212.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/xrkixnpkexe |
Source: alg.exe, 0000000D.00000003.2007443563.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1999368202.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1957228645.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1972777177.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1955019744.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1983866160.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1966658212.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2016629204.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/xrkixnpkqlbauh |
Source: alg.exe, 0000000D.00000003.1966658212.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1957228645.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1957847112.0000000000538000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1955019744.000000000052C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/xrkixnpkt |
Source: alg.exe, 0000000D.00000003.2046169214.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2181291982.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2089955706.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2067214816.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2079601241.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2200527185.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2125759526.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1966658212.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2163395398.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2025611759.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.000000000052A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2106093399.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2229080820.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1983866160.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1972777177.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032480249.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2040378345.0000000000539000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007443563.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2246556685.000000000053A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1944474303.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1957228645.0000000000529000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/yhikx |
Source: alg.exe, 0000000D.00000003.1790797442.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1575202487.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1553956256.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1798107286.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23:80/enP |
Source: alg.exe, 0000000D.00000003.1543980844.0000000000509000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23:80/gedtsq |
Source: alg.exe, 0000000D.00000003.1955254799.0000000000509000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23:80/xrkixnpk |
Source: alg.exe, 0000000D.00000003.1955254799.0000000000509000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1944621326.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23:80/yhikx |
Source: alg.exe, 0000000D.00000003.1790797442.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1790563475.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1790699822.000000000053A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/aopfhnckuovs |
Source: RegSvcs.exe, 00000008.00000002.1601150507.0000000001223000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/c |
Source: alg.exe, 0000000D.00000003.1838038969.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/fkj |
Source: alg.exe, 0000000D.00000003.1838038969.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/fkjgs |
Source: alg.exe, 0000000D.00000003.1878733120.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/mtrjsdrytjxvslm |
Source: alg.exe, 0000000D.00000003.1878733120.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/mtrjsdrytjxvslm#$u |
Source: alg.exe, 0000000D.00000003.1798107286.0000000000521000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1838038969.0000000000521000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1798107286.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/reeuv |
Source: alg.exe, 0000000D.00000003.1798107286.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/reeuv#$u |
Source: RegSvcs.exe, 00000008.00000002.1601150507.000000000120D000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000008.00000002.1601150507.0000000001223000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/wt |
Source: alg.exe, 0000000D.00000003.1790797442.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1798107286.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197:80/aopfhnckuovs |
Source: alg.exe, 0000000D.00000003.1838038969.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197:80/fkjv |
Source: alg.exe, 0000000D.00000003.1914053502.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1892690377.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1878733120.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1907846105.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197:80/mtrjsdrytjxvslmP |
Source: alg.exe, 0000000D.00000003.1798107286.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197:80/reeuv |
Source: RegSvcs.exe, 00000008.00000002.1601150507.000000000120D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197:80/wt |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0 |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05 |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L |
Source: MUH030425.exe | String found in binary or memory: http://insimsniffer.codeplex.com/project/feeds/rss?ProjectRSSFeed=codeplex%3a%2f%2frelease%2finsimsn |
Source: RegSvcs.exe, RegSvcs.exe, 00000008.00000002.1600484490.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/json |
Source: RegSvcs.exe, 00000008.00000002.1601150507.00000000011F3000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000008.00000002.1603192431.0000000003330000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://k1d5.icu/TP341/index.php |
Source: RegSvcs.exe, 00000008.00000002.1603192431.0000000003330000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://k1d5.icu/TP341/index.phph |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0C |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0N |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.thawte.com0 |
Source: MUH030425.exe, 00000000.00000002.1686714780.0000000002B51000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: alg.exe, 0000000D.00000003.1955445110.0000000001840000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.fwiwk.biz/?ts=fENsZWFuUGVwcGVybWludEJsYWNrfHw1Y2U4NHxidWNrZXQwNzB8fHx8fHw2N2M2YmI1NjUxOD |
Source: alg.exe, 0000000D.00000003.1955019744.0000000000545000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2089955706.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2197748874.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2276640960.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007952814.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2107290818.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2118070130.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1999368202.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032480249.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2016629204.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1967145828.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1983866160.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2047366590.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2079601241.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2153120949.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2259482527.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2161214560.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2143416467.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2040378345.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1972777177.0000000000547000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.fwiwk.biz/xrkixnpk?usid=18&utid=30152687444 |
Source: alg.exe, 0000000D.00000003.1955254799.0000000000509000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.fwiwk.biz:80/xrkixnpk?usid=18&utid=30152687444Pn: |
Source: alg.exe, 0000000D.00000003.1544371487.0000000001790000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/?ts=fENsZWFuUGVwcGVybWludEJsYWNrfHw1Y2U4NHxidWNrZXQwMTV8fHx8fHw2N2M2YmIyZDM4 |
Source: RegSvcs.exe, 00000008.00000002.1601150507.0000000001235000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/cygwkoswoy?usid=18&utid=30152678086 |
Source: alg.exe, 0000000D.00000003.1878733120.0000000000521000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/gedtsq?usid=18&utid=30152678479 |
Source: alg.exe, 0000000D.00000003.1790797442.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1892690377.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1838038969.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1878733120.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1543980844.0000000000509000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1575202487.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1553956256.000000000050A000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1798107286.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz:80/gedtsq?usid=18&utid=30152678479 |
Source: alg.exe, 0000000D.00000003.1955019744.0000000000545000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2089955706.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2197748874.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2276640960.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007952814.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2107290818.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2118070130.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1999368202.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032480249.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2016629204.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1967145828.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1983866160.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2047366590.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2079601241.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2153120949.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2259482527.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2161214560.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2143416467.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2040378345.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1972777177.0000000000547000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww7.fwiwk.biz/yhikx?usid=18&utid=30152687280 |
Source: alg.exe, 0000000D.00000003.1955254799.0000000000509000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1944621326.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww7.fwiwk.biz:80/yhikx?usid=18&utid=30152687280P |
Source: RegSvcs.exe, 00000008.00000002.1601150507.0000000001235000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww7.przvgke.biz/b?usid=18&utid=30152678348 |
Source: RegSvcs.exe, 00000008.00000002.1601150507.0000000001243000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww7.przvgke.biz/b?usid=18&utid=30152678348Sje |
Source: alg.exe, 0000000D.00000003.1555833531.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1576172278.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1790563475.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1914915915.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1838038969.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1798846224.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1908959853.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1932675425.0000000000529000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1917871727.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1797899601.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1907606835.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1572794877.000000000052C000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1892475238.000000000052C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww7.przvgke.biz/en?usid=18&utid=30152678739 |
Source: alg.exe, 0000000D.00000003.1553956256.000000000050A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww7.przvgke.biz:80/en?usid=18&utid=30152678739P |
Source: alg.exe, 0000000D.00000003.2270507357.0000000000680000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.autoitscript.com/autoit3/ |
Source: alg.exe, 0000000D.00000003.2270739736.0000000000680000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.autoitscript.com/autoit3/8 |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.mozilla.com/en-US/blocklist/ |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.mozilla.com0 |
Source: alg.exe, 0000000D.00000003.1636988813.0000000001650000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: alg.exe, 0000000D.00000003.2112196038.0000000000430000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://aus5.mozilla.org/update/6/%PRODUCT%/%VERSION%/%BUILD_ID%/%BUILD_TARGET%/%LOCALE%/%CHANNEL%/% |
Source: alg.exe, 0000000D.00000003.2038996262.0000000001540000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://clients2.google.com/cr/report |
Source: alg.exe, 0000000D.00000003.2038996262.0000000001540000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://clients2.google.com/cr/report.. |
Source: alg.exe, 0000000D.00000003.1695292605.0000000001650000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://clients2.google.com/service/update2/crxFailed |
Source: alg.exe, 0000000D.00000003.1695827522.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1695966946.0000000001650000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://clients2.google.com/service/update2/crxHKEY_LOCAL_MACHINE |
Source: alg.exe, 0000000D.00000003.2112271794.0000000000430000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://crash-reports.mozilla.com/submit?id= |
Source: RegSvcs.exe, RegSvcs.exe, 00000008.00000002.1600484490.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://dotbit.me/a/ |
Source: alg.exe, 0000000D.00000003.1955445110.0000000001840000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1543338864.00000000014A0000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1544371487.0000000001790000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1954786173.0000000001510000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://euob.seaskydvd.com/sxp/i/224f85302aa2b6ec30aac9a85da2cbf9.js |
Source: alg.exe, 0000000D.00000003.2095233929.0000000000400000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://firefox.settings.services.mozilla.com/v1 |
Source: alg.exe, 0000000D.00000003.2095233929.0000000000400000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://firefox.settings.services.mozilla.com/v1MaybeMigrateVersion1118.0.1.0in |
Source: setup.exe1.13.dr | String found in binary or memory: https://github.com/pq-crystals/kyber/commit/28413dfbf523fdde181246451c2bd77199c0f7ff |
Source: setup.exe1.13.dr | String found in binary or memory: https://github.com/pq-crystals/kyber/commit/28413dfbf523fdde181246451c2bd77199c0f7ffDilithium2Dilith |
Source: alg.exe, 0000000D.00000003.2112343455.0000000000430000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://hg.mozilla.org/releases/mozilla-release/rev/68e4c357d26c5a1f075a1ec0c696d4fe684ed881 |
Source: alg.exe, 0000000D.00000003.2112343455.0000000000430000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://hg.mozilla.org/releases/mozilla-release/rev/68e4c357d26c5a1f075a1ec0c696d4fe684ed881118.0.1 |
Source: alg.exe, 0000000D.00000003.2095519854.0000000000400000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://incoming.telemetry.mozilla.org/submit/default-browser-agent/default-browser/1/Hash |
Source: alg.exe, 0000000D.00000003.2111979719.0000000000430000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://incoming.telemetry.mozilla.org/submit/firefox-launcher-process/launcher-process-failure/1/ |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_authorize.srf |
Source: RegSvcs.exe, 00000008.00000002.1601150507.0000000001235000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000008.00000002.1601150507.0000000001253000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_authorize.srf?client_id=00000000480728C5&scope=service::ssl.live.com: |
Source: RegSvcs.exe, 00000008.00000002.1601150507.0000000001235000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033 |
Source: RegSvcs.exe, 00000008.00000002.1601150507.00000000011F3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033ws |
Source: RegSvcs.exe, 00000008.00000002.1605184982.00000000040E0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srfic |
Source: RegSvcs.exe, 00000008.00000002.1605184982.00000000040E0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_logout.sr8 |
Source: RegSvcs.exe, 00000008.00000002.1605184982.00000000040E0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_logout.srf |
Source: RegSvcs.exe, 00000008.00000002.1601150507.00000000011A8000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000008.00000002.1601150507.0000000001235000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_logout.srf?client_id=00000000480728C5&redirect_uri=https://login.live |
Source: alg.exe, 0000000D.00000003.1955445110.0000000001840000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1954786173.0000000001510000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://parking3.parklogic.com/page/enhance.js?pcId=12&domain=fwiwk.biz |
Source: alg.exe, 0000000D.00000003.1543338864.00000000014A0000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1544371487.0000000001790000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://parking3.parklogic.com/page/enhance.js?pcId=12&domain=przvgke.biz |
Source: alg.exe, 0000000D.00000003.1544371487.0000000001790000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://pcnatrk.net/munin/a/tr/click |
Source: alg.exe, 0000000D.00000003.1955445110.0000000001840000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://trkpcna.net/munin/a/tr/click |
Source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: RegSvcs.exe, 00000008.00000002.1601150507.0000000001253000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1955019744.0000000000545000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2089955706.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2197748874.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2276640960.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2007952814.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2107290818.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2062612258.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2118070130.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1999368202.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2032480249.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2016629204.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1967145828.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1555956968.000000000052F000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1552930830.0000000000532000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1983866160.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2047366590.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2079601241.0000000000547000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2153120949.0000000000546000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1572794877.0000000000532000.00000004.00000020.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.2259482527.0000000000546000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C27B71 | 8_2_02C27B71 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C600D9 | 8_2_02C600D9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C251EE | 8_2_02C251EE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C55980 | 8_2_02C55980 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C26EAF | 8_2_02C26EAF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C639A3 | 8_2_02C639A3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C6515C | 8_2_02C6515C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C5C7F0 | 8_2_02C5C7F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C27F80 | 8_2_02C27F80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C53780 | 8_2_02C53780 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 8_2_02C5D580 | 8_2_02C5D580 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 17_2_00B9A810 | 17_2_00B9A810 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 17_2_00B77C00 | 17_2_00B77C00 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 17_2_00B779F0 | 17_2_00B779F0 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 17_2_00BA2D40 | 17_2_00BA2D40 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 17_2_00B9EEB0 | 17_2_00B9EEB0 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 17_2_00B992A0 | 17_2_00B992A0 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 17_2_00B993B0 | 17_2_00B993B0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 21_2_00427C00 | 21_2_00427C00 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 21_2_0044A810 | 21_2_0044A810 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 21_2_00452D40 | 21_2_00452D40 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 21_2_004279F0 | 21_2_004279F0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 21_2_004492A0 | 21_2_004492A0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 21_2_0044EEB0 | 21_2_0044EEB0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 21_2_004493B0 | 21_2_004493B0 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 22_2_009BA810 | 22_2_009BA810 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 22_2_00997C00 | 22_2_00997C00 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 22_2_009979F0 | 22_2_009979F0 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 22_2_009C2D40 | 22_2_009C2D40 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 22_2_009BEEB0 | 22_2_009BEEB0 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 22_2_009B92A0 | 22_2_009B92A0 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 22_2_009B93B0 | 22_2_009B93B0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 23_2_00C07C00 | 23_2_00C07C00 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 23_2_00C2A810 | 23_2_00C2A810 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 23_2_00C079F0 | 23_2_00C079F0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 23_2_00C32D40 | 23_2_00C32D40 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 23_2_00C292A0 | 23_2_00C292A0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 23_2_00C2EEB0 | 23_2_00C2EEB0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 23_2_00C293B0 | 23_2_00C293B0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_00C97C00 | 24_2_00C97C00 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_00CBA810 | 24_2_00CBA810 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_00C979F0 | 24_2_00C979F0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_00CC2D40 | 24_2_00CC2D40 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_00CB92A0 | 24_2_00CB92A0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_00CBEEB0 | 24_2_00CBEEB0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_00CB93B0 | 24_2_00CB93B0 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 25_2_004C7C00 | 25_2_004C7C00 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 25_2_004EA810 | 25_2_004EA810 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 25_2_004F2D40 | 25_2_004F2D40 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 25_2_004C79F0 | 25_2_004C79F0 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 25_2_004E92A0 | 25_2_004E92A0 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 25_2_004EEEB0 | 25_2_004EEEB0 |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Code function: 25_2_004E93B0 | 25_2_004E93B0 |
Source: C:\Windows\System32\Locator.exe | Code function: 27_2_0076A810 | 27_2_0076A810 |
Source: C:\Windows\System32\Locator.exe | Code function: 27_2_00747C00 | 27_2_00747C00 |
Source: C:\Windows\System32\Locator.exe | Code function: 27_2_00772D40 | 27_2_00772D40 |
Source: C:\Windows\System32\Locator.exe | Code function: 27_2_007479F0 | 27_2_007479F0 |
Source: C:\Windows\System32\Locator.exe | Code function: 27_2_0076EEB0 | 27_2_0076EEB0 |
Source: C:\Windows\System32\Locator.exe | Code function: 27_2_007692A0 | 27_2_007692A0 |
Source: C:\Windows\System32\Locator.exe | Code function: 27_2_007693B0 | 27_2_007693B0 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 29_2_004A7C00 | 29_2_004A7C00 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 29_2_004CA810 | 29_2_004CA810 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 29_2_004D2D40 | 29_2_004D2D40 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 29_2_004A79F0 | 29_2_004A79F0 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 29_2_004C92A0 | 29_2_004C92A0 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 29_2_004CEEB0 | 29_2_004CEEB0 |
Source: C:\Windows\System32\SensorDataService.exe | Code function: 29_2_004C93B0 | 29_2_004C93B0 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 30_2_006C7C00 | 30_2_006C7C00 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 30_2_006EA810 | 30_2_006EA810 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 30_2_006F2D40 | 30_2_006F2D40 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 30_2_006C79F0 | 30_2_006C79F0 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 30_2_006E92A0 | 30_2_006E92A0 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 30_2_006EEEB0 | 30_2_006EEEB0 |
Source: C:\Windows\System32\snmptrap.exe | Code function: 30_2_006E93B0 | 30_2_006E93B0 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 31_2_004A7C00 | 31_2_004A7C00 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 31_2_004CA810 | 31_2_004CA810 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 31_2_004D2D40 | 31_2_004D2D40 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 31_2_004A79F0 | 31_2_004A79F0 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 31_2_004C92A0 | 31_2_004C92A0 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 31_2_004CEEB0 | 31_2_004CEEB0 |
Source: C:\Windows\System32\Spectrum.exe | Code function: 31_2_004C93B0 | 31_2_004C93B0 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 32_2_00D9A810 | 32_2_00D9A810 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 32_2_00D77C00 | 32_2_00D77C00 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 32_2_00D779F0 | 32_2_00D779F0 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 32_2_00DA2D40 | 32_2_00DA2D40 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 32_2_00D9EEB0 | 32_2_00D9EEB0 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 32_2_00D992A0 | 32_2_00D992A0 |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Code function: 32_2_00D993B0 | 32_2_00D993B0 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 34_2_006D7C00 | 34_2_006D7C00 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 34_2_006FA810 | 34_2_006FA810 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 34_2_00702D40 | 34_2_00702D40 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 34_2_006D79F0 | 34_2_006D79F0 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 34_2_006F92A0 | 34_2_006F92A0 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 34_2_006FEEB0 | 34_2_006FEEB0 |
Source: C:\Windows\System32\TieringEngineService.exe | Code function: 34_2_006F93B0 | 34_2_006F93B0 |
Source: C:\Windows\System32\AgentService.exe | Code function: 36_2_00BAA810 | 36_2_00BAA810 |
Source: C:\Windows\System32\AgentService.exe | Code function: 36_2_00B87C00 | 36_2_00B87C00 |
Source: C:\Windows\System32\AgentService.exe | Code function: 36_2_00B879F0 | 36_2_00B879F0 |
Source: C:\Windows\System32\AgentService.exe | Code function: 36_2_00BB2D40 | 36_2_00BB2D40 |
Source: C:\Windows\System32\AgentService.exe | Code function: 36_2_00BAEEB0 | 36_2_00BAEEB0 |
Source: C:\Windows\System32\AgentService.exe | Code function: 36_2_00BA92A0 | 36_2_00BA92A0 |
Source: C:\Windows\System32\AgentService.exe | Code function: 36_2_00BA93B0 | 36_2_00BA93B0 |
Source: C:\Windows\System32\vds.exe | Code function: 37_2_00C27C00 | 37_2_00C27C00 |
Source: C:\Windows\System32\vds.exe | Code function: 37_2_00C4A810 | 37_2_00C4A810 |
Source: C:\Windows\System32\vds.exe | Code function: 37_2_00C279F0 | 37_2_00C279F0 |
Source: C:\Windows\System32\vds.exe | Code function: 37_2_00C52D40 | 37_2_00C52D40 |
Source: C:\Windows\System32\vds.exe | Code function: 37_2_00C492A0 | 37_2_00C492A0 |
Source: C:\Windows\System32\vds.exe | Code function: 37_2_00C4EEB0 | 37_2_00C4EEB0 |
Source: C:\Windows\System32\vds.exe | Code function: 37_2_00C493B0 | 37_2_00C493B0 |
Source: C:\Windows\System32\wbengine.exe | Code function: 39_2_0078A810 | 39_2_0078A810 |
Source: C:\Windows\System32\wbengine.exe | Code function: 39_2_00767C00 | 39_2_00767C00 |
Source: C:\Windows\System32\wbengine.exe | Code function: 39_2_00792D40 | 39_2_00792D40 |
Source: C:\Windows\System32\wbengine.exe | Code function: 39_2_007679F0 | 39_2_007679F0 |
Source: C:\Windows\System32\wbengine.exe | Code function: 39_2_0078EEB0 | 39_2_0078EEB0 |
Source: C:\Windows\System32\wbengine.exe | Code function: 39_2_007892A0 | 39_2_007892A0 |
Source: C:\Windows\System32\wbengine.exe | Code function: 39_2_007893B0 | 39_2_007893B0 |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: webio.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: rasadhlp.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: drprov.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ntlanman.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: davclnt.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: davhlpr.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: cscapi.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: browcli.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: appvpolicy.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: wtsapi32.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: netapi32.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: samcli.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: appmanagementconfiguration.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: apphelp.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Section loaded: windowscodecs.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: tapi32.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: credui.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: fxstiff.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: fxsresm.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: ualapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: mpr.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: ntmarta.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: mpr.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: ntmarta.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtctm.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtcprx.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtclog.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mtxclu.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: winmm.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: xolehlp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mtxclu.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: ktmw32.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: comres.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtcvsp1res.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mtxoci.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: oci.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: cscapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: firewallapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: fwbase.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: fwpolicyiomgr.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: hid.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: dxgi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: devobj.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mfplat.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: rtworkq.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: windows.devices.perception.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mediafoundation.defaultperceptionprovider.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: windows.devices.enumeration.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: structuredquery.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: windows.globalization.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: bcp47mrm.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: icu.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mswb7.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: devdispitemprovider.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: powrprof.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: spectrumsyncclient.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: umpdc.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: perceptionsimulationextensions.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: hid.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: holographicruntimes.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: perceptiondevice.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: spatialstore.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: esent.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: analogcommonproxystub.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: capabilityaccessmanagerclient.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: windows.devices.enumeration.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: structuredquery.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: windows.globalization.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: bcp47mrm.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: icu.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: mswb7.dll | |
Source: C:\Windows\System32\Spectrum.exe | Section loaded: devdispitemprovider.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: apphelp.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: libcrypto.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: esent.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\TieringEngineService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: fltlib.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: activeds.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: adsldpc.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\AgentService.exe | Section loaded: appmanagementconfiguration.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: osuninst.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: vdsutil.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: bcd.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: uexfat.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: ulib.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: ifsutil.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: devobj.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: uudf.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: untfs.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: ufat.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: fmifs.dll | |
Source: C:\Windows\System32\vds.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: vssapi.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: virtdisk.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: bcd.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: spp.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: netapi32.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: xmllite.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: wer.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: vsstrace.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: fltlib.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\wbengine.exe | Section loaded: ntmarta.dll | |
Source: | Binary string: api-ms-win-crt-runtime-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\TextExtractor.pdb444 source: alg.exe, 0000000D.00000003.1687730891.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\TextExtractor.pdb source: alg.exe, 0000000D.00000003.1687730891.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\jjs_objs\jjs.pdb source: jjs.exe.13.dr |
Source: | Binary string: mavinject32.pdbGCTL source: alg.exe, 0000000D.00000003.1873376292.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1876347240.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PresentationFontCache.pdb source: alg.exe, 0000000D.00000003.1602398119.00000000016C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-file-l1-2-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-debug-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\setup.exe.pdbOGP source: setup.exe1.13.dr |
Source: | Binary string: api-ms-win-core-sysinfo-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-filesystem-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: plugin-container.pdb source: alg.exe, 0000000D.00000003.2202633741.0000000000650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WebInstaller\AcroMiniServicesUpdater.pdb source: alg.exe, 0000000D.00000003.1637621243.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x64\ship\click2run\x-none\InspectorOfficeGadget.pdb source: alg.exe, 0000000D.00000003.1863510269.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ShowAppPickerForPDF\Release_x64\ShowAppPickerForPDF.pdb source: alg.exe, 0000000D.00000003.1812452407.0000000001450000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1806949825.0000000001660000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-heap-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp, api-ms-win-core-heap-l1-1-0.dll.8.dr |
Source: | Binary string: d:\dbs\el\omr\target\x86\ship\dcf\x-none\Common.ShowHelp.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: Common.ShowHelp.exe.13.dr |
Source: | Binary string: Microsoft.VisualBasic.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: vcruntime140.i386.pdbGCTL source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-environment-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: pingsender.pdb source: alg.exe, 0000000D.00000003.2182345698.0000000000650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\mozglue\build\mozglue.pdb11 source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-processthreads-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-console-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-private-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.ni.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb)) source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msvcp140.i386.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-profile-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: maintenanceservice.pdb source: alg.exe, 0000000D.00000003.2131240760.0000000000440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\setup.exe.pdb source: setup.exe1.13.dr |
Source: | Binary string: firefox.pdb source: alg.exe, 0000000D.00000003.2112410522.0000000000430000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x64\ship\click2run\x-none\InspectorOfficeGadget.pdbY source: alg.exe, 0000000D.00000003.1863510269.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-time-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: firefox.pdbP source: alg.exe, 0000000D.00000003.2112410522.0000000000430000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WCChromeNativeMessagingHost.pdb source: alg.exe, 0000000D.00000003.1724231457.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-handle-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\workspace\CR-Windows-x64-Client-Builder\x64\Release\CRWindowsClientService.pdb source: alg.exe, 0000000D.00000003.1742573812.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\b\s\w\ir\cache\builder\src\out\Release_x64\chrome_pwa_launcher.exe.pdb source: alg.exe, 0000000D.00000003.1947973037.0000000001480000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-synch-l1-2-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ShowAppPickerForPDF\Release_x64\ShowAppPickerForPDF.pdb$$ source: alg.exe, 0000000D.00000003.1812452407.0000000001450000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1806949825.0000000001660000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-processenvironment-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Windows.Forms.pdb.> source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: mscorlib.ni.pdbRSDS source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-core-localization-l1-2-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Configuration.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\deploy\tmp\ssvagent\obj\ssvagent.pdb source: ssvagent.exe.13.dr |
Source: | Binary string: minidump-analyzer.pdb source: alg.exe, 0000000D.00000003.2157918575.0000000000650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-processthreads-l1-1-1.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-namedpipe-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-multibyte-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp, api-ms-win-crt-multibyte-l1-1-0.dll.8.dr |
Source: | Binary string: api-ms-win-core-rtlsupport-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msvcp140.i386.pdbGCTL source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-crt-process-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Drawing.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.pdb4 source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-core-interlocked-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release\Plug_ins\pi_brokers\32BitMAPIBroker.pdb source: alg.exe, 0000000D.00000003.1774099876.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-heap-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: AppVShNotify.pdbGCTL source: alg.exe, 0000000D.00000003.1859682808.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-string-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\work\p4\splinters\Splinters\S\BuildResults\bin\Win32\ReaderRelease\FullTrustNotifier\FullTrustNotifier.pdb77.GCTL source: alg.exe, 0000000D.00000003.1794989425.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-locale-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\PkgInstaller\base\ntsetup\SrvPack.Main\tools\sfxcab\sfxcab\objfre\i386\sfxcab.pdb source: alg.exe, 0000000D.00000003.1838763806.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1839825345.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1846357220.0000000001530000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\mozglue\build\mozglue.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Accessibility.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: ADelRCP_Exec.pdb source: alg.exe, 0000000D.00000003.1696706041.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss3.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-memory-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\freebl\freebl_freebl3\freebl3.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: crashreporter.pdb source: alg.exe, 0000000D.00000003.2059367986.0000000000400000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\plug_ins\pi_brokers\MSRMSPIBroker.pdbAAAGCTL source: alg.exe, 0000000D.00000003.1790232245.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-stdio-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WCChromeNativeMessagingHost.pdb888 source: alg.exe, 0000000D.00000003.1724231457.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Xml.ni.pdbRSDS# source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.Core.ni.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-core-util-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: locator.pdb source: Locator.exe.8.dr |
Source: | Binary string: api-ms-win-core-synch-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-errorhandling-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ADelRCP_Exec.pdbCC9 source: alg.exe, 0000000D.00000003.1696706041.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\freebl\freebl_freebl3\freebl3.pdbZZ source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-file-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: private_browsing.pdb source: alg.exe, 0000000D.00000003.2212108302.0000000000670000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-convert-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\PkgInstaller\base\ntsetup\SrvPack.Main\tools\sfxcab\sfxcab\objfre\i386\sfxcab.pdbU source: alg.exe, 0000000D.00000003.1838763806.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1839825345.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1846357220.0000000001530000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WebInstaller\AcroMiniServicesUpdater.pdbT source: alg.exe, 0000000D.00000003.1637621243.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\workspace\CR-Windows-x64-Client-Builder\x64\Release\CRWindowsClientService.pdbGG source: alg.exe, 0000000D.00000003.1742573812.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\jdk\objs\jjs_objs\jjs.pdb source: jjs.exe.13.dr |
Source: | Binary string: ucrtbase.pdbUGP source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mavinject32.pdb source: alg.exe, 0000000D.00000003.1873376292.0000000001650000.00000004.00001000.00020000.00000000.sdmp, alg.exe, 0000000D.00000003.1876347240.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: pixuBt.pdb source: MUH030425.exe, WER4A31.tmp.dmp.18.dr |
Source: | Binary string: 64BitMAPIBroker.pdb source: alg.exe, 0000000D.00000003.1781474310.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Configuration.ni.pdbRSDScUN source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: d:\dbs\el\omr\target\x86\ship\dcf\x-none\Common.ShowHelp.pdb source: Common.ShowHelp.exe.13.dr |
Source: | Binary string: System.Drawing.pdb( source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: E:\jenkins\workspace\NGL_WORKFLOW\build\master\win64\Release\Acrobat\project\win\ngl-workflow\x64\Release (Acrobat)\adobe_licensing_wf_helper_acro.pdb source: alg.exe, 0000000D.00000003.1770420067.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\softoken\legacydb\legacydb_nssdbm3\nssdbm3.pdb-- source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: private_browsing.pdbp source: alg.exe, 0000000D.00000003.2212108302.0000000000670000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\work\p4\splinters\Splinters\S\BuildResults\bin\Win32\ReaderRelease\FullTrustNotifier\FullTrustNotifier.pdb source: alg.exe, 0000000D.00000003.1794989425.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release\Plug_ins\pi_brokers\32BitMAPIBroker.pdb@@ source: alg.exe, 0000000D.00000003.1774099876.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Xml.ni.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.ni.pdbRSDS source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\plug_ins\pi_brokers\MSRMSPIBroker.pdb source: alg.exe, 0000000D.00000003.1790232245.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: maintenanceservice.pdb` source: alg.exe, 0000000D.00000003.2131240760.0000000000440000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Accessibility.pdbD(L source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\Eula.pdb source: alg.exe, 0000000D.00000003.1747818920.0000000001650000.00000004.00001000.00020000.00000000.sdmp, Eula.exe.13.dr |
Source: | Binary string: System.Configuration.ni.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-core-datetime-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-conio-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\deploy\tmp\ssvagent\obj\ssvagent.pdb<<7 source: ssvagent.exe.13.dr |
Source: | Binary string: api-ms-win-crt-math-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Xml.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: vcruntime140.i386.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-crt-utility-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Windows.Forms.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: z:\build\build\src\obj-firefox\security\nss\lib\softoken\legacydb\legacydb_nssdbm3\nssdbm3.pdb source: RegSvcs.exe, 00000008.00000002.1609934065.0000000004EB0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-timezone-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: pixuBt.pdbSHA256 source: MUH030425.exe, WER4A31.tmp.dmp.18.dr |
Source: | Binary string: api-ms-win-core-string-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PresentationFontCache.pdbHt^t Pt_CorExeMainmscoree.dll source: alg.exe, 0000000D.00000003.1602398119.00000000016C0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: api-ms-win-core-file-l2-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: locator.pdbGCTL source: Locator.exe.8.dr |
Source: | Binary string: api-ms-win-core-libraryloader-l1-1-0.pdb source: RegSvcs.exe, 00000008.00000002.1607219329.0000000004A60000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: System.Core.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: default-browser-agent.pdb source: alg.exe, 0000000D.00000003.2095519854.0000000000400000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: updater.pdb source: alg.exe, 0000000D.00000003.2233883361.0000000000650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: AppVShNotify.pdb source: alg.exe, 0000000D.00000003.1859682808.0000000001650000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\Eula.pdb888 source: alg.exe, 0000000D.00000003.1747818920.0000000001650000.00000004.00001000.00020000.00000000.sdmp, Eula.exe.13.dr |
Source: | Binary string: System.Xml.pdb@\ source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.ni.pdb source: WER4A31.tmp.dmp.18.dr |
Source: | Binary string: System.Core.ni.pdbRSDS source: WER4A31.tmp.dmp.18.dr |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\pingsender.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\vds.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\snmptrap.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\Spectrum.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Windows Media Player\wmpnetwk.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\Locator.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\7-Zip\7z.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.134\Installer\chrmstp.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\AppVClient.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\crashreporter.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\SysWOW64\perfhost.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\7-Zip\7zG.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\msiexec.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.134\Installer\setup.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\TieringEngineService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\firefox.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\updater.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\7-Zip\Uninstall.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\FXSSVC.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.134\elevation_service.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\SensorDataService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\msdtc.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\wbem\WmiApSrv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\alg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files\7-Zip\7zFM.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.134\notification_helper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\wbengine.exe | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\VSSVC.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\SearchIndexer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\private_browsing.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\Install\{9DD40E31-8782-438B-BCFD-713DE1B3090F}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.134\chrome_pwa_launcher.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\AgentService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | System file written: C:\Windows\System32\OpenSSH\ssh-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\plugin-container.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\msvcp140.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\snmptrap.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\Spectrum.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\Windows Media Player\wmpnetwk.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\7-Zip\7z.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\117.0.5938.134\Installer\chrmstp.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\AppVClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\7-Zip\7zG.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\SysWOW64\perfhost.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\117.0.5938.134\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\ucrtbase.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\7-Zip\Uninstall.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\FXSSVC.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\SensorDataService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\wbem\WmiApSrv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\alg.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-utility-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\SearchIndexer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\Install\{9DD40E31-8782-438B-BCFD-713DE1B3090F}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\nss3.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\117.0.5938.134\chrome_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\OpenSSH\ssh-agent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\vds.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\Locator.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\nssdbm3.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\msiexec.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\freebl3.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-processthreads-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\TieringEngineService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-math-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\Google\Chrome\Application\117.0.5938.134\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\msdtc.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\vcruntime140.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Program Files\7-Zip\7zFM.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\117.0.5938.134\notification_helper.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\MUH030425.exe | File created: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\VSSVC.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\wbengine.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\softokn3.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\mozglue.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Windows\System32\AgentService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | File created: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\Windows Media Player\wmpnetwk.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\117.0.5938.134\Installer\chrmstp.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7z.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7zG.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\lynchtmlconv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\117.0.5938.134\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\Uninstall.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Windows\System32\wbem\WmiApSrv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-utility-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Windows\System32\SearchIndexer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\excelcnv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\Install\{9DD40E31-8782-438B-BCFD-713DE1B3090F}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\nss3.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\117.0.5938.134\chrome_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\nssdbm3.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Windows\System32\msiexec.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\freebl3.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-processthreads-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-math-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\117.0.5938.134\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7zFM.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\117.0.5938.134\notification_helper.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Windows\System32\VSSVC.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\softokn3.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\32DE8C23\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\MUH030425.exe | Queries volume information: C:\Users\user\Desktop\MUH030425.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MUH030425.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\AppVClient.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Queries volume information: C:\Users\user\AppData\Roaming\wBBaygjR.exe VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\wBBaygjR.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | |
Source: C:\Windows\System32\FXSSVC.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\FXSSVC.exe | Queries volume information: C:\ProgramData\Microsoft\Windows NT\MSFax\Queue\TST4BB8.tmp VolumeInformation | |
Source: C:\Windows\System32\FXSSVC.exe | Queries volume information: C:\ProgramData\Microsoft\Windows NT\MSFax\TST4D9D.tmp VolumeInformation | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\msdtc.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\Locator.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\SensorDataService.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\snmptrap.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\Spectrum.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\OpenSSH\ssh-agent.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\TieringEngineService.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\AgentService.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\vds.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\wbengine.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\SysWOW64\cmd.exe | Queries volume information: C:\ VolumeInformation | |