Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.00000000040DF000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000004157000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1340022400.00000000061C0000.00000004.08000000.00040000.00000000.sdmp |
Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.00000000040DF000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000004157000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1340022400.00000000061C0000.00000004.08000000.00040000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdbSHA256}Lq source: VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdb source: VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: MSBuild.exe, 00000006.00000002.2529966193.00000000028E1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000006.00000002.2529966193.00000000029A0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000006.00000002.2529966193.00000000029BC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com |
Source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.00000000041CD000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000006.00000002.2529966193.00000000028E1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000006.00000002.2529966193.00000000029A0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000006.00000002.2528526488.0000000000CFD000.00000004.00000020.00020000.00000000.sdmp, MSBuild.exe, 00000006.00000002.2526883031.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://ocsp.digicert.com0 |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://ocsp.digicert.com0A |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://ocsp.digicert.com0C |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://ocsp.digicert.com0X |
Source: VoaY6Clwfh.exe, 00000002.00000002.1310707607.0000000002F21000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000006.00000002.2529966193.00000000028E1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000006.00000002.2529966193.00000000029A0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: VoaY6Clwfh.exe | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.00000000041CD000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000006.00000002.2526883031.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://account.dyn.com/ |
Source: VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-net |
Source: VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-netJ |
Source: VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-neti |
Source: VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/11564914/23354; |
Source: VoaY6Clwfh.exe, 00000002.00000002.1310707607.0000000002F21000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/14436606/23354 |
Source: VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/2152978/23354 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_02DC12D0 | 2_2_02DC12D0 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_02DC12A7 | 2_2_02DC12A7 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_02DC1858 | 2_2_02DC1858 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_02DC1856 | 2_2_02DC1856 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057F3DD8 | 2_2_057F3DD8 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057F7CDB | 2_2_057F7CDB |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057FDFE8 | 2_2_057FDFE8 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057FF830 | 2_2_057FF830 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057F6368 | 2_2_057F6368 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057FC260 | 2_2_057FC260 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057F0718 | 2_2_057F0718 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057F0713 | 2_2_057F0713 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057FA0E0 | 2_2_057FA0E0 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057FA0CF | 2_2_057FA0CF |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057FF3A8 | 2_2_057FF3A8 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_057FC250 | 2_2_057FC250 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05812490 | 2_2_05812490 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05812458 | 2_2_05812458 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058545F8 | 2_2_058545F8 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_0585A62B | 2_2_0585A62B |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058589B0 | 2_2_058589B0 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058545E8 | 2_2_058545E8 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05859CA0 | 2_2_05859CA0 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_0585942C | 2_2_0585942C |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05859453 | 2_2_05859453 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058589A0 | 2_2_058589A0 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_0585901F | 2_2_0585901F |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058592BE | 2_2_058592BE |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058F0007 | 2_2_058F0007 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058F0040 | 2_2_058F0040 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058F5FE0 | 2_2_058F5FE0 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058F5FF0 | 2_2_058F5FF0 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058F928F | 2_2_058F928F |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058F66A8 | 2_2_058F66A8 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_058FE678 | 2_2_058FE678 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05AEB7E8 | 2_2_05AEB7E8 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05AE7DD0 | 2_2_05AE7DD0 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05AE3CE0 | 2_2_05AE3CE0 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05AE1A40 | 2_2_05AE1A40 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05AE80F7 | 2_2_05AE80F7 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05AE93D8 | 2_2_05AE93D8 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05AE4A39 | 2_2_05AE4A39 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05AE1A30 | 2_2_05AE1A30 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05AE4A48 | 2_2_05AE4A48 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05B6F7E8 | 2_2_05B6F7E8 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05B68438 | 2_2_05B68438 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05B6F7DA | 2_2_05B6F7DA |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05CFFAC0 | 2_2_05CFFAC0 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05CFE168 | 2_2_05CFE168 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05CE0040 | 2_2_05CE0040 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05CE0006 | 2_2_05CE0006 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 6_2_00C6A4C8 | 6_2_00C6A4C8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 6_2_00C6D970 | 6_2_00C6D970 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 6_2_00C64AC0 | 6_2_00C64AC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 6_2_00C63EA8 | 6_2_00C63EA8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 6_2_00C641F0 | 6_2_00C641F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 6_2_054C1408 | 6_2_054C1408 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 6_2_054C3668 | 6_2_054C3668 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 6_2_054C3D50 | 6_2_054C3D50 |
Source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.00000000041CD000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename2ef0ab37-7f3e-4594-af6b-a038ff0febc5.exe4 vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.00000000040DF000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000004157000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1310707607.0000000002F21000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000000.1284214265.0000000000482000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameVmaatinyfkd.exeP vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000004024000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameMpuwuftvi.dll" vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1310707607.00000000032EB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename2ef0ab37-7f3e-4594-af6b-a038ff0febc5.exe4 vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1309216190.000000000124E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1340022400.00000000061C0000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe, 00000002.00000002.1335760544.00000000055B0000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameMpuwuftvi.dll" vs VoaY6Clwfh.exe |
Source: VoaY6Clwfh.exe | Binary or memory string: OriginalFilenameVmaatinyfkd.exeP vs VoaY6Clwfh.exe |
Source: 2.2.VoaY6Clwfh.exe.4107288.3.raw.unpack, TaskSecurity.cs | Security API names: Microsoft.Win32.TaskScheduler.TaskSecurity.GetAccessControlSectionsFromChanges() |
Source: 2.2.VoaY6Clwfh.exe.4107288.3.raw.unpack, TaskSecurity.cs | Security API names: System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(System.Security.AccessControl.AccessRule) |
Source: 2.2.VoaY6Clwfh.exe.4107288.3.raw.unpack, TaskFolder.cs | Security API names: Microsoft.Win32.TaskScheduler.TaskFolder.GetAccessControl(System.Security.AccessControl.AccessControlSections) |
Source: 2.2.VoaY6Clwfh.exe.4107288.3.raw.unpack, TaskPrincipal.cs | Security API names: System.Security.Principal.WindowsIdentity.GetCurrent() |
Source: 2.2.VoaY6Clwfh.exe.4107288.3.raw.unpack, Task.cs | Security API names: Microsoft.Win32.TaskScheduler.Task.GetAccessControl(System.Security.AccessControl.AccessControlSections) |
Source: 2.2.VoaY6Clwfh.exe.4107288.3.raw.unpack, User.cs | Security API names: System.Security.Principal.SecurityIdentifier.Translate(System.Type) |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.00000000040DF000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000004157000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1340022400.00000000061C0000.00000004.08000000.00040000.00000000.sdmp |
Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: VoaY6Clwfh.exe, 00000002.00000002.1329151593.00000000040DF000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000004157000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1340022400.00000000061C0000.00000004.08000000.00040000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdbSHA256}Lq source: VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdb source: VoaY6Clwfh.exe, 00000002.00000002.1338831614.0000000005B10000.00000004.08000000.00040000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003F28000.00000004.00000800.00020000.00000000.sdmp, VoaY6Clwfh.exe, 00000002.00000002.1329151593.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp |
Source: 2.2.VoaY6Clwfh.exe.4107288.3.raw.unpack, ReflectionHelper.cs | .Net Code: InvokeMethod |
Source: 2.2.VoaY6Clwfh.exe.4107288.3.raw.unpack, ReflectionHelper.cs | .Net Code: InvokeMethod |
Source: 2.2.VoaY6Clwfh.exe.4107288.3.raw.unpack, XmlSerializationHelper.cs | .Net Code: ReadObjectProperties |
Source: 2.2.VoaY6Clwfh.exe.5b10000.8.raw.unpack, TypeModel.cs | .Net Code: TryDeserializeList |
Source: 2.2.VoaY6Clwfh.exe.5b10000.8.raw.unpack, ListDecorator.cs | .Net Code: Read |
Source: 2.2.VoaY6Clwfh.exe.5b10000.8.raw.unpack, TypeSerializer.cs | .Net Code: CreateInstance |
Source: 2.2.VoaY6Clwfh.exe.5b10000.8.raw.unpack, TypeSerializer.cs | .Net Code: EmitCreateInstance |
Source: 2.2.VoaY6Clwfh.exe.5b10000.8.raw.unpack, TypeSerializer.cs | .Net Code: EmitCreateIfNull |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_02DC1849 pushad ; ret | 2_2_02DC1855 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05816DB5 push esi; retf | 2_2_05816DB6 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05816D54 push esi; retf | 2_2_05816D56 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_0585D0DF pushad ; ret | 2_2_0585D0E5 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05858B35 push ebp; ret | 2_2_05858B36 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05AED582 pushfd ; retf | 2_2_05AED589 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05B6EAB6 push es; iretd | 2_2_05B6EAB9 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05CD0391 push edx; retf | 2_2_05CD039E |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05CD095F push ebx; retf | 2_2_05CD098C |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05CE1D57 push esp; iretd | 2_2_05CE1D5B |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05CE1C9B push esp; iretd | 2_2_05CE1C9C |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Code function: 2_2_05CE1E27 push esp; iretd | 2_2_05CE1E2B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 6_2_054CC840 push es; ret | 6_2_054CC850 |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: MSBuild.exe, 00000006.00000002.2529966193.00000000029BC000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: VMware |
Source: MSBuild.exe, 00000006.00000002.2529966193.00000000029BC000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: vmware |
Source: VoaY6Clwfh.exe, 00000002.00000002.1310707607.0000000002F21000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: q 1:en-CH:Microsoft|VMWare|Virtual |
Source: VoaY6Clwfh.exe, 00000002.00000002.1310707607.0000000002F21000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: VMware|VIRTUAL|A M I|Xen |
Source: VoaY6Clwfh.exe, 00000002.00000002.1310707607.0000000002F21000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: q 1:en-CH:VMware|VIRTUAL|A M I|Xen |
Source: VoaY6Clwfh.exe, 00000002.00000002.1310707607.0000000002F21000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Microsoft|VMWare|Virtual |
Source: MSBuild.exe, 00000006.00000002.2526883031.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Binary or memory string: VMwareVBox |
Source: MSBuild.exe, 00000006.00000002.2528526488.0000000000D22000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Queries volume information: C:\Users\user\Desktop\VoaY6Clwfh.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\VoaY6Clwfh.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |