Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: uolmaTGkHh.exe, 00000000.00000002.944240515.0000000006690000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000466A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000046E2000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: uolmaTGkHh.exe, 00000000.00000002.944240515.0000000006690000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000466A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000046E2000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdbSHA256}Lq source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdb source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.199.215.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.18.98.62 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.18.21.226 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.18.21.226 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.18.21.226 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.18.21.226 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: uolmaTGkHh.exe | String found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0 |
Source: uolmaTGkHh.exe | String found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U |
Source: uolmaTGkHh.exe | String found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0 |
Source: uolmaTGkHh.exe | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G |
Source: uolmaTGkHh.exe | String found in binary or memory: http://crl.globalsign.com/root-r6.crl0G |
Source: uolmaTGkHh.exe, 00000000.00000002.921530343.00000000016E4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.mic= |
Source: MSBuild.exe, 00000001.00000002.2165009454.0000000002811000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000001.00000002.2165009454.00000000028C8000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000001.00000002.2165009454.00000000028E4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com |
Source: uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.0000000004759000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000001.00000002.2161121086.0000000000802000.00000040.00000400.00020000.00000000.sdmp, MSBuild.exe, 00000001.00000002.2165009454.0000000002811000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000001.00000002.2165009454.00000000028C8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: MSBuild.exe, 00000001.00000002.2163050550.0000000000ABE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line/?fields=hostinge |
Source: uolmaTGkHh.exe | String found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C |
Source: uolmaTGkHh.exe | String found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F |
Source: uolmaTGkHh.exe | String found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U |
Source: uolmaTGkHh.exe | String found in binary or memory: http://ocsp.globalsign.com/rootr30; |
Source: uolmaTGkHh.exe | String found in binary or memory: http://ocsp2.globalsign.com/rootr606 |
Source: uolmaTGkHh.exe, 00000000.00000002.924966672.00000000034C1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000001.00000002.2165009454.0000000002811000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000001.00000002.2165009454.00000000028C8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: uolmaTGkHh.exe | String found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A |
Source: uolmaTGkHh.exe | String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0? |
Source: uolmaTGkHh.exe | String found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0 |
Source: uolmaTGkHh.exe | String found in binary or memory: http://secure.globalsign.com/cacert/root-r3.crt06 |
Source: uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.0000000004759000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000001.00000002.2161121086.0000000000802000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://account.dyn.com/ |
Source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-net |
Source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-netJ |
Source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-neti |
Source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/11564914/23354; |
Source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.924966672.00000000034C1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/14436606/23354 |
Source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/2152978/23354 |
Source: uolmaTGkHh.exe | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C1A86 | 0_2_018C1A86 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C539C | 0_2_018C539C |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C53BD | 0_2_018C53BD |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C5221 | 0_2_018C5221 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C55B6 | 0_2_018C55B6 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C5534 | 0_2_018C5534 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C548F | 0_2_018C548F |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C2CF3 | 0_2_018C2CF3 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C276A | 0_2_018C276A |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C2778 | 0_2_018C2778 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_018C5622 | 0_2_018C5622 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_059B5C08 | 0_2_059B5C08 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_059B81B0 | 0_2_059B81B0 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_059B9B23 | 0_2_059B9B23 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_059B1FF8 | 0_2_059B1FF8 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_059B1FE8 | 0_2_059B1FE8 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_059BE0D8 | 0_2_059BE0D8 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_059B5BF8 | 0_2_059B5BF8 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D205E0 | 0_2_05D205E0 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D21998 | 0_2_05D21998 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D205D1 | 0_2_05D205D1 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D21991 | 0_2_05D21991 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D21941 | 0_2_05D21941 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D2854F | 0_2_05D2854F |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D2F3D8 | 0_2_05D2F3D8 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D27E98 | 0_2_05D27E98 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D27E89 | 0_2_05D27E89 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D2F630 | 0_2_05D2F630 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DD9FF8 | 0_2_05DD9FF8 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DE6E18 | 0_2_05DE6E18 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DE4CB8 | 0_2_05DE4CB8 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DE0448 | 0_2_05DE0448 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DE0420 | 0_2_05DE0420 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DE6E08 | 0_2_05DE6E08 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DE1910 | 0_2_05DE1910 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DE1902 | 0_2_05DE1902 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_060403DB | 0_2_060403DB |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_0604DA50 | 0_2_0604DA50 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_06049AE1 | 0_2_06049AE1 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_0604A708 | 0_2_0604A708 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_0604A718 | 0_2_0604A718 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_06047740 | 0_2_06047740 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_06047750 | 0_2_06047750 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_0604640D | 0_2_0604640D |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_06040006 | 0_2_06040006 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_0604F048 | 0_2_0604F048 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_0604DD77 | 0_2_0604DD77 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_061A33E0 | 0_2_061A33E0 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_061A9AB8 | 0_2_061A9AB8 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_061AA8E8 | 0_2_061AA8E8 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_061A5421 | 0_2_061A5421 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_061A5480 | 0_2_061A5480 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_061A9568 | 0_2_061A9568 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_061D0006 | 0_2_061D0006 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_061D0040 | 0_2_061D0040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 1_2_00DBA4C8 | 1_2_00DBA4C8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 1_2_00DBD970 | 1_2_00DBD970 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 1_2_00DB4AC0 | 1_2_00DB4AC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 1_2_00DB3EA8 | 1_2_00DB3EA8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 1_2_00DB41F0 | 1_2_00DB41F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 1_2_05451408 | 1_2_05451408 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 1_2_05453668 | 1_2_05453668 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Code function: 1_2_05453D50 | 1_2_05453D50 |
Source: uolmaTGkHh.exe, 00000000.00000002.944240515.0000000006690000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000002.940332104.0000000005AF0000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameUzpdtchkbj.dll" vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000002.921530343.00000000016AE000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000002.937794730.0000000004759000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename2ef0ab37-7f3e-4594-af6b-a038ff0febc5.exe4 vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000002.937794730.000000000466A000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000002.937794730.00000000046E2000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000000.906130505.0000000001072000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameFalsesgwcej.exeD vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000002.924966672.00000000035D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename2ef0ab37-7f3e-4594-af6b-a038ff0febc5.exe4 vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe, 00000000.00000002.924966672.00000000034C1000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename vs uolmaTGkHh.exe |
Source: uolmaTGkHh.exe | Binary or memory string: OriginalFilenameFalsesgwcej.exeD vs uolmaTGkHh.exe |
Source: 0.2.uolmaTGkHh.exe.476e828.3.raw.unpack, cPs8D.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.uolmaTGkHh.exe.476e828.3.raw.unpack, 72CF8egH.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.uolmaTGkHh.exe.476e828.3.raw.unpack, G5CXsdn.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.uolmaTGkHh.exe.476e828.3.raw.unpack, 3uPsILA6U.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.2.uolmaTGkHh.exe.476e828.3.raw.unpack, 6oQOw74dfIt.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.uolmaTGkHh.exe.476e828.3.raw.unpack, aMIWm.cs | Cryptographic APIs: 'CreateDecryptor', 'TransformBlock' |
Source: 0.2.uolmaTGkHh.exe.476e828.3.raw.unpack, 3QjbQ514BDx.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.uolmaTGkHh.exe.476e828.3.raw.unpack, 3QjbQ514BDx.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: uolmaTGkHh.exe, 00000000.00000002.944240515.0000000006690000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000466A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000046E2000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: uolmaTGkHh.exe, 00000000.00000002.944240515.0000000006690000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000466A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000046E2000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdbSHA256}Lq source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdb source: uolmaTGkHh.exe, 00000000.00000002.942785106.0000000005FD0000.00000004.08000000.00040000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.000000000454A000.00000004.00000800.00020000.00000000.sdmp, uolmaTGkHh.exe, 00000000.00000002.937794730.00000000044D2000.00000004.00000800.00020000.00000000.sdmp |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_059D5189 pushad ; iretd | 0_2_059D5A39 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_059D51A8 pushad ; iretd | 0_2_059D5A39 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05D2C359 push cs; ret | 0_2_05D2C35C |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DD0007 push esp; retf | 0_2_05DD0031 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DD3AD7 push ebx; retf | 0_2_05DD3ADA |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_05DE449D pushfd ; retf | 0_2_05DE449E |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_06043467 push ebp; retf | 0_2_06043469 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_06043460 push ebp; retf | 0_2_06043461 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_060431BF push cs; iretd | 0_2_060431C7 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_0604D1C0 push es; ret | 0_2_0604D270 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_061A264C push es; retf | 0_2_061A2658 |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Code function: 0_2_061D6908 push eax; retf | 0_2_061D690D |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: MSBuild.exe, 00000001.00000002.2165009454.0000000002845000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: VMware |
Source: MSBuild.exe, 00000001.00000002.2165009454.0000000002845000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: vmware |
Source: uolmaTGkHh.exe, 00000000.00000002.924966672.00000000034C1000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: q 1:en-CH:Microsoft|VMWare|Virtual |
Source: uolmaTGkHh.exe, 00000000.00000002.924966672.00000000034C1000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: VMware|VIRTUAL|A M I|Xen |
Source: uolmaTGkHh.exe, 00000000.00000002.924966672.00000000034C1000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: q 1:en-CH:VMware|VIRTUAL|A M I|Xen |
Source: uolmaTGkHh.exe, 00000000.00000002.924966672.00000000034C1000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Microsoft|VMWare|Virtual |
Source: MSBuild.exe, 00000001.00000002.2161121086.0000000000802000.00000040.00000400.00020000.00000000.sdmp | Binary or memory string: VMwareVBox |
Source: MSBuild.exe, 00000001.00000002.2167921829.0000000005356000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Queries volume information: C:\Users\user\Desktop\uolmaTGkHh.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\uolmaTGkHh.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |