Source: | Binary string: C:\work\p4\splinters\Splinters\S\BuildResults\bin\Win32\ReaderRelease\FullTrustNotifier\FullTrustNotifier.pdb77.GCTL source: armsvc.exe, 00000001.00000003.1797114631.0000000000970000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\DCB\CBT_Main\BuildResults\bin\Win32\Release\armsvc.pdb source: DHL Original Shipment Document PDF.exe, 00000000.00000003.1046178567.0000000003F00000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\PkgInstaller\base\ntsetup\SrvPack.Main\tools\sfxcab\sfxcab\objfre\i386\sfxcab.pdb source: armsvc.exe, 00000001.00000003.1859341688.00000000008A0000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1867974546.0000000000740000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1857838325.0000000000960000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msiexec.pdb source: armsvc.exe, 00000001.00000003.1135157354.00000000020B0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcrobatInfo.pdb source: armsvc.exe, 00000001.00000003.1418322264.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ssh-agent.pdb source: armsvc.exe, 00000001.00000003.1249219536.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\TextExtractor.pdb444 source: armsvc.exe, 00000001.00000003.1581340089.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\TextExtractor.pdb source: armsvc.exe, 00000001.00000003.1581340089.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ADelRCP_Exec.pdb source: armsvc.exe, 00000001.00000003.1609165745.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msiexec.pdbGCTL source: armsvc.exe, 00000001.00000003.1135157354.00000000020B0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mavinject32.pdbGCTL source: armsvc.exe, 00000001.00000003.1917070144.0000000000970000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1920320834.0000000000980000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PresentationFontCache.pdb source: armsvc.exe, 00000001.00000003.1081334918.00000000020B0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: sppsvc.pdb source: sppsvc.exe.1.dr |
Source: | Binary string: PerceptionSimulationService.pdb source: armsvc.exe, 00000001.00000003.1143163743.00000000020B0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: MFPMP.pdbUGP source: svchost.exe, 00000004.00000003.1220427692.0000000002E1A000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000004.00000003.1220228607.0000000002E1B000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000004.00000003.1220478974.0000000002E24000.00000004.00000020.00020000.00000000.sdmp, yrC1hsBFkVzDRlK9HaXIw3.exe, 0000000F.00000003.1190705972.0000000000464000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb source: DHL Original Shipment Document PDF.exe, 00000000.00000003.1058529436.0000000004DE0000.00000004.00001000.00020000.00000000.sdmp, DHL Original Shipment Document PDF.exe, 00000000.00000003.1057666992.00000000049B0000.00000004.00001000.00020000.00000000.sdmp, svchost.exe, svchost.exe, 00000004.00000002.1252659211.000000000359E000.00000040.00001000.00020000.00000000.sdmp, svchost.exe, 00000004.00000002.1252659211.0000000003400000.00000040.00001000.00020000.00000000.sdmp, svchost.exe, 00000004.00000003.1148825415.0000000003200000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000004.00000003.1144848733.0000000003000000.00000004.00000020.00020000.00000000.sdmp, mfpmp.exe, 00000012.00000003.1258238312.0000000003727000.00000004.00000020.00020000.00000000.sdmp, mfpmp.exe, 00000012.00000002.2333170601.0000000003A6E000.00000040.00001000.00020000.00000000.sdmp, mfpmp.exe, 00000012.00000003.1253219757.000000000357E000.00000004.00000020.00020000.00000000.sdmp, mfpmp.exe, 00000012.00000002.2333170601.00000000038D0000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WebInstaller\AcroMiniServicesUpdater.pdb source: armsvc.exe, 00000001.00000003.1540482509.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Spectrum.pdb source: Spectrum.exe.1.dr |
Source: | Binary string: MsSense.pdbGCTL source: armsvc.exe, 00000001.00000003.1179121995.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: MsSense.pdb source: armsvc.exe, 00000001.00000003.1179121995.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x64\ship\click2run\x-none\InspectorOfficeGadget.pdb source: armsvc.exe, 00000001.00000003.1895911729.0000000000960000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ShowAppPickerForPDF\Release_x64\ShowAppPickerForPDF.pdb source: armsvc.exe, 00000001.00000003.1806727903.0000000000920000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816085373.0000000000740000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: svchost.pdb source: mfpmp.exe, 00000012.00000002.2341935250.0000000003EFC000.00000004.10000000.00040000.00000000.sdmp, mfpmp.exe, 00000012.00000002.2307560381.0000000003328000.00000004.00000020.00020000.00000000.sdmp, yrC1hsBFkVzDRlK9HaXIw3.exe, 00000023.00000000.1344341457.000000000336C000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 00000027.00000002.1584211512.0000000023D2C000.00000004.80000000.00040000.00000000.sdmp |
Source: | Binary string: WmiApSrv.pdbGCTL source: armsvc.exe, 00000001.00000003.1322855026.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: svchost.pdbUGP source: mfpmp.exe, 00000012.00000002.2341935250.0000000003EFC000.00000004.10000000.00040000.00000000.sdmp, mfpmp.exe, 00000012.00000002.2307560381.0000000003328000.00000004.00000020.00020000.00000000.sdmp, yrC1hsBFkVzDRlK9HaXIw3.exe, 00000023.00000000.1344341457.000000000336C000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 00000027.00000002.1584211512.0000000023D2C000.00000004.80000000.00040000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WCChromeNativeMessagingHost.pdb888 source: armsvc.exe, 00000001.00000003.1660622739.00000000008F0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Acrobat_SL.pdb((( source: armsvc.exe, 00000001.00000003.1436031953.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Spectrum.pdbGCTL source: Spectrum.exe.1.dr |
Source: | Binary string: locator.pdb source: armsvc.exe, 00000001.00000003.1170145523.00000000020A0000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1176058150.0000000001F90000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: DiagnosticsHub.StandardCollector.Service.pdbGCTL source: DHL Original Shipment Document PDF.exe, 00000000.00000003.1063455377.0000000004090000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ADelRCP_Exec.pdbCC9 source: armsvc.exe, 00000001.00000003.1609165745.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcroBroker.pdb source: armsvc.exe, 00000001.00000003.1448753071.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: Acrobat_SL.pdb source: armsvc.exe, 00000001.00000003.1436031953.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: E:\PkgInstaller\base\ntsetup\SrvPack.Main\tools\sfxcab\sfxcab\objfre\i386\sfxcab.pdbU source: armsvc.exe, 00000001.00000003.1859341688.00000000008A0000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1867974546.0000000000740000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1857838325.0000000000960000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WebInstaller\AcroMiniServicesUpdater.pdbT source: armsvc.exe, 00000001.00000003.1540482509.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: sppsvc.pdbGCTL source: sppsvc.exe.1.dr |
Source: | Binary string: C:\workspace\CR-Windows-x64-Client-Builder\x64\Release\CRWindowsClientService.pdbGG source: armsvc.exe, 00000001.00000003.1697731153.0000000000900000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcrobatInfo.pdb))) source: armsvc.exe, 00000001.00000003.1418322264.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: mavinject32.pdb source: armsvc.exe, 00000001.00000003.1917070144.0000000000970000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1920320834.0000000000980000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msdtcexe.pdbGCTL source: armsvc.exe, 00000001.00000003.1127633370.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: 64BitMAPIBroker.pdb source: armsvc.exe, 00000001.00000003.1778356482.0000000000900000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: maintenanceservice.pdb source: armsvc.exe, 00000001.00000003.1119902499.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: snmptrap.pdbGCTL source: armsvc.exe, 00000001.00000003.1206706830.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerceptionSimulationService.pdbGCTL source: armsvc.exe, 00000001.00000003.1143163743.00000000020B0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerfHost.pdbGCTL source: armsvc.exe, 00000001.00000003.1159092648.0000000002090000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1168394527.0000000001F90000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1162022580.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x64\ship\click2run\x-none\InspectorOfficeGadget.pdbY source: armsvc.exe, 00000001.00000003.1895911729.0000000000960000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\Work\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: yrC1hsBFkVzDRlK9HaXIw3.exe, 0000000F.00000000.1177061989.00000000005DF000.00000002.00000001.01000000.00000004.sdmp, yrC1hsBFkVzDRlK9HaXIw3.exe, 00000023.00000002.2297260939.00000000005DF000.00000002.00000001.01000000.00000004.sdmp |
Source: | Binary string: E:\jenkins\workspace\NGL_WORKFLOW\build\master\win64\Release\Acrobat\project\win\ngl-workflow\x64\Release (Acrobat)\adobe_licensing_wf_helper_acro.pdb source: armsvc.exe, 00000001.00000003.1758932973.00000000008F0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ADNotificationManager\Viewer Release_x64\ADNotificationManager.pdb source: ADNotificationManager.exe.1.dr |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\WCChromeNativeMessagingHost.pdb source: armsvc.exe, 00000001.00000003.1660622739.00000000008F0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\work\p4\splinters\Splinters\S\BuildResults\bin\Win32\ReaderRelease\FullTrustNotifier\FullTrustNotifier.pdb source: armsvc.exe, 00000001.00000003.1797114631.0000000000970000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\workspace\CR-Windows-x64-Client-Builder\x64\Release\CRWindowsClientService.pdb source: armsvc.exe, 00000001.00000003.1697731153.0000000000900000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PerfHost.pdb source: armsvc.exe, 00000001.00000003.1159092648.0000000002090000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1168394527.0000000001F90000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1162022580.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release\Plug_ins\pi_brokers\32BitMAPIBroker.pdb@@ source: armsvc.exe, 00000001.00000003.1764551748.0000000000970000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: MFPMP.pdb source: svchost.exe, 00000004.00000003.1220427692.0000000002E1A000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000004.00000003.1220228607.0000000002E1B000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000004.00000003.1220478974.0000000002E24000.00000004.00000020.00020000.00000000.sdmp, yrC1hsBFkVzDRlK9HaXIw3.exe, 0000000F.00000003.1190705972.0000000000464000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: maintenanceservice.pdb` source: armsvc.exe, 00000001.00000003.1119902499.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: SgrmBroker.pdbGCTL source: armsvc.exe, 00000001.00000003.1197039027.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ShowAppPickerForPDF\Release_x64\ShowAppPickerForPDF.pdb$$ source: armsvc.exe, 00000001.00000003.1806727903.0000000000920000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816085373.0000000000740000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdbUGP source: DHL Original Shipment Document PDF.exe, 00000000.00000003.1058529436.0000000004DE0000.00000004.00001000.00020000.00000000.sdmp, DHL Original Shipment Document PDF.exe, 00000000.00000003.1057666992.00000000049B0000.00000004.00001000.00020000.00000000.sdmp, svchost.exe, 00000004.00000002.1252659211.000000000359E000.00000040.00001000.00020000.00000000.sdmp, svchost.exe, 00000004.00000002.1252659211.0000000003400000.00000040.00001000.00020000.00000000.sdmp, svchost.exe, 00000004.00000003.1148825415.0000000003200000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000004.00000003.1144848733.0000000003000000.00000004.00000020.00020000.00000000.sdmp, mfpmp.exe, 00000012.00000003.1258238312.0000000003727000.00000004.00000020.00020000.00000000.sdmp, mfpmp.exe, 00000012.00000002.2333170601.0000000003A6E000.00000040.00001000.00020000.00000000.sdmp, mfpmp.exe, 00000012.00000003.1253219757.000000000357E000.00000004.00000020.00020000.00000000.sdmp, mfpmp.exe, 00000012.00000002.2333170601.00000000038D0000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: WmiApSrv.pdb source: armsvc.exe, 00000001.00000003.1322855026.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: TieringEngineService.pdb source: armsvc.exe, 00000001.00000003.1260827094.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: TieringEngineService.pdbGCTL source: armsvc.exe, 00000001.00000003.1260827094.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\Eula.pdb source: armsvc.exe, 00000001.00000003.1708844859.0000000000900000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ALG.pdb source: DHL Original Shipment Document PDF.exe, 00000000.00000003.1050939203.0000000003F20000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: msdtcexe.pdb source: armsvc.exe, 00000001.00000003.1127633370.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: DiagnosticsHub.StandardCollector.Service.pdb source: DHL Original Shipment Document PDF.exe, 00000000.00000003.1063455377.0000000004090000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ALG.pdbGCTL source: DHL Original Shipment Document PDF.exe, 00000000.00000003.1050939203.0000000003F20000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: PresentationFontCache.pdbHt^t Pt_CorExeMainmscoree.dll source: armsvc.exe, 00000001.00000003.1081334918.00000000020B0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: locator.pdbGCTL source: armsvc.exe, 00000001.00000003.1170145523.00000000020A0000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1176058150.0000000001F90000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\AcroBroker.pdbTTT source: armsvc.exe, 00000001.00000003.1448753071.0000000002030000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\Acrobat\Installers\ADNotificationManager\Viewer Release_x64\ADNotificationManager.pdb22 source: ADNotificationManager.exe.1.dr |
Source: | Binary string: SgrmBroker.pdb source: armsvc.exe, 00000001.00000003.1197039027.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: ssh-agent.pdbX source: armsvc.exe, 00000001.00000003.1249219536.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: AppVShNotify.pdb source: armsvc.exe, 00000001.00000003.1891985859.0000000000750000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: snmptrap.pdb source: armsvc.exe, 00000001.00000003.1206706830.00000000020A0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release\Plug_ins\pi_brokers\32BitMAPIBroker.pdb source: armsvc.exe, 00000001.00000003.1764551748.0000000000970000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: D:\T\BuildResults\bin\Release_x64\Eula.pdb888 source: armsvc.exe, 00000001.00000003.1708844859.0000000000900000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: AppVShNotify.pdbGCTL source: armsvc.exe, 00000001.00000003.1891985859.0000000000750000.00000004.00001000.00020000.00000000.sdmp |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\wbem\WmiApSrv.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\vds.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | System file written: C:\Windows\System32\alg.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\7-Zip\7zFM.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\snmptrap.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\Spectrum.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Windows Media Player\wmpnetwk.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\Locator.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | System file written: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\7-Zip\7z.exe | Jump to behavior |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | System file written: C:\Windows\System32\AppVClient.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\SysWOW64\perfhost.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\7-Zip\7zG.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\msiexec.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\VSSVC.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\wbengine.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\SearchIndexer.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\TieringEngineService.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\AgentService.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\7-Zip\Uninstall.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\FXSSVC.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\SgrmBroker.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\OpenSSH\ssh-agent.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\sppsvc.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\SensorDataService.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Windows\System32\msdtc.exe | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | System file written: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to behavior |
Source: armsvc.exe, 00000001.00000003.1774465553.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1665507777.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150/ |
Source: armsvc.exe, 00000001.00000003.1774921644.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150/f |
Source: armsvc.exe, 00000001.00000003.1737461235.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1750002483.00000000006A8000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1690852057.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1719723025.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1675473221.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1729481996.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1673962751.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1665217708.00000000006A9000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1664959944.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1757476953.00000000006A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150/v |
Source: armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1781183252.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1774786396.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1790247195.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://13.251.16.150/vgf |
Source: armsvc.exe, 00000001.00000003.1817094379.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1819838646.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006C3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://165.160.13.20/usnhsmdsjyqpwtmv |
Source: armsvc.exe, 00000001.00000003.1819838646.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1819838646.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://165.160.13.20/vwbvgj |
Source: DHL Original Shipment Document PDF.exe, 00000000.00000002.1077140822.0000000000C9A000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1149701624.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1643910161.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1883216416.00000000006A3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1384298264.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1625467325.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1091858221.0000000000692000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1092172583.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1691512595.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1149701624.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/ |
Source: armsvc.exe, 00000001.00000003.1111649707.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1106025081.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1092172583.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/ajkphssjnch& |
Source: armsvc.exe, 00000001.00000003.1149701624.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/d |
Source: DHL Original Shipment Document PDF.exe, 00000000.00000002.1077140822.0000000000C9A000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1691512595.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/f |
Source: armsvc.exe, 00000001.00000003.1883216416.00000000006A3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1915528007.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/it |
Source: DHL Original Shipment Document PDF.exe, 00000000.00000002.1077140822.0000000000C9A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/s |
Source: armsvc.exe, 00000001.00000003.1915528007.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/v |
Source: DHL Original Shipment Document PDF.exe, 00000000.00000002.1077140822.0000000000C87000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/vs |
Source: DHL Original Shipment Document PDF.exe, 00000000.00000002.1077520052.0000000000CD9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/vs-11E |
Source: armsvc.exe, 00000001.00000003.1149701624.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1643910161.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1675473221.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1384298264.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1673962751.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1625467325.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1665217708.00000000006A9000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1664959944.00000000006A2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107/yxowiallopowd |
Source: DHL Original Shipment Document PDF.exe, 00000000.00000002.1077140822.0000000000C9A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.141.10.107:80/vs |
Source: armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1819838646.00000000006AB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.237.28.253/ |
Source: armsvc.exe, 00000001.00000003.1800157264.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.237.28.253/a |
Source: armsvc.exe, 00000001.00000003.1800157264.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.237.28.253/s |
Source: armsvc.exe, 00000001.00000003.1800157264.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.237.28.253/u |
Source: armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.237.28.253/uK |
Source: armsvc.exe, 00000001.00000003.1800157264.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://18.237.28.253/z |
Source: armsvc.exe, 00000001.00000003.1774921644.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1750002483.00000000006A8000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1750966117.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1850328223.00000000006A6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/ |
Source: armsvc.exe, 00000001.00000003.1750966117.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/% |
Source: armsvc.exe, 00000001.00000003.1750966117.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/9 |
Source: armsvc.exe, 00000001.00000003.1750966117.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/do |
Source: armsvc.exe, 00000001.00000003.1750966117.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/doi |
Source: armsvc.exe, 00000001.00000003.1750966117.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/fxea |
Source: armsvc.exe, 00000001.00000003.1750966117.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/fxea4 |
Source: armsvc.exe, 00000001.00000003.1750966117.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/fxea: |
Source: armsvc.exe, 00000001.00000003.1750966117.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/fxeax |
Source: armsvc.exe, 00000001.00000003.1750966117.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/h |
Source: armsvc.exe, 00000001.00000003.1838113163.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1850328223.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1914259949.00000000006CB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1878704536.00000000006CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/jbrhhqusdro(i |
Source: armsvc.exe, 00000001.00000003.1850328223.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006C3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://208.117.43.225/kjikijsewqakmca |
Source: armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1819838646.00000000006AB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.94.10.34// |
Source: armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1819838646.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://3.94.10.34/rgwn |
Source: armsvc.exe, 00000001.00000003.1883216416.00000000006A3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1915528007.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.215.158.160/V |
Source: armsvc.exe, 00000001.00000003.1883216416.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1850328223.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1915528007.00000000006C3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.215.158.160/qxge.L |
Source: DHL Original Shipment Document PDF.exe, 00000000.00000002.1077140822.0000000000C48000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1105877749.0000000000692000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1790709964.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1800157264.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1883216416.00000000006A3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1838113163.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1106025081.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1074851122.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1850328223.00000000006A6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1111576700.0000000000692000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.219.59.42/ |
Source: armsvc.exe, 00000001.00000003.1790709964.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1111649707.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1106025081.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.219.59.42/6a |
Source: armsvc.exe, 00000001.00000003.1838113163.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1850328223.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1914259949.00000000006CB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1878704536.00000000006CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.219.59.42/dlltbcafpn |
Source: armsvc.exe, 00000001.00000003.1914259949.00000000006CB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1878704536.00000000006CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.219.59.42/jvhfvcaeelsFn |
Source: armsvc.exe, 00000001.00000003.1790247195.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.219.59.42/kbawedyyrydxhsw |
Source: DHL Original Shipment Document PDF.exe, 00000000.00000002.1077140822.0000000000C87000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.219.59.42/lu |
Source: armsvc.exe, 00000001.00000003.1074663290.0000000000692000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.219.59.42/rjywjxjdasndsc |
Source: armsvc.exe, 00000001.00000003.1106025081.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1092172583.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1074851122.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.219.59.42/s |
Source: armsvc.exe, 00000001.00000003.1790247195.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.219.59.42/v |
Source: armsvc.exe, 00000001.00000003.1092172583.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1074851122.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.219.59.42/z |
Source: armsvc.exe, 00000001.00000003.1737461235.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1750002483.00000000006A8000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1757476953.00000000006A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.227.7.138/ |
Source: armsvc.exe, 00000001.00000003.1737897252.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.227.7.138/6a |
Source: armsvc.exe, 00000001.00000003.1737897252.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.227.7.138/ef |
Source: armsvc.exe, 00000001.00000003.1737897252.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.227.7.138/efs |
Source: armsvc.exe, 00000001.00000003.1737897252.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.227.7.138/pjo |
Source: armsvc.exe, 00000001.00000003.1915528007.00000000006C3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1915528007.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.227.7.138/yamxvkp |
Source: armsvc.exe, 00000001.00000003.1729846861.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.246.200.160/ |
Source: armsvc.exe, 00000001.00000003.1729846861.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.246.200.160/h |
Source: armsvc.exe, 00000001.00000003.1729846861.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://34.246.200.160/z |
Source: armsvc.exe, 00000001.00000003.1737461235.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1790247195.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1690852057.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1719723025.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1675473221.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1781422211.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1729481996.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1673962751.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1781183252.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1111576700.0000000000692000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.200.87.10/ |
Source: armsvc.exe, 00000001.00000003.1111649707.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.200.87.10/6af |
Source: armsvc.exe, 00000001.00000003.1790709964.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1781422211.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.200.87.10/a |
Source: armsvc.exe, 00000001.00000003.1111649707.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1674642968.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.200.87.10/ef |
Source: armsvc.exe, 00000001.00000003.1751358520.0000000000661000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1738423204.0000000000660000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1666283151.0000000000660000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.200.87.10/pmoqrlgttds |
Source: armsvc.exe, 00000001.00000003.1111649707.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://44.200.87.10/z |
Source: armsvc.exe, 00000001.00000003.1645592348.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://47.129.31.212/ |
Source: armsvc.exe, 00000001.00000003.1645592348.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1645592348.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://47.129.31.212/mxcjrnsv |
Source: armsvc.exe, 00000001.00000003.1645592348.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://47.129.31.212/mxcjrnsvs |
Source: armsvc.exe, 00000001.00000003.1643910161.00000000006A2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://47.129.31.212/~ |
Source: armsvc.exe, 00000001.00000003.1131899721.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/2d |
Source: armsvc.exe, 00000001.00000003.1720118872.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1729846861.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/ef |
Source: armsvc.exe, 00000001.00000003.1131899721.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/t |
Source: armsvc.exe, 00000001.00000003.1737461235.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1750002483.00000000006A8000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1719723025.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1774465553.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1729481996.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1781183252.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1757476953.00000000006A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://72.52.178.23/u0 |
Source: armsvc.exe, 00000001.00000003.1624651789.00000000006D2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1625467325.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1384971585.00000000006BA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1623775644.00000000006CE000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1384298264.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/ |
Source: armsvc.exe, 00000001.00000003.1625467325.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/9 |
Source: armsvc.exe, 00000001.00000003.1645592348.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1625467325.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/_ |
Source: armsvc.exe, 00000001.00000003.1625467325.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1384298264.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/imubctmyh |
Source: armsvc.exe, 00000001.00000003.1737461235.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1750002483.00000000006A8000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1790247195.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1690852057.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1643910161.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1719723025.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1675473221.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1774465553.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1729481996.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1673962751.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1625467325.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1665217708.00000000006A9000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1664959944.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1781183252.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1757476953.00000000006A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/xvhmahkpisso |
Source: armsvc.exe, 00000001.00000003.1625467325.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://82.112.184.197/z |
Source: armsvc.exe, 00000001.00000003.1915528007.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://acwjcqqv.biz/~ |
Source: armsvc.exe, 00000001.00000003.1790247195.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1781183252.00000000006AA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://bumxkqgxu.biz/ |
Source: armsvc.exe, 00000001.00000003.1737461235.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1750002483.00000000006A8000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1790247195.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1774465553.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1838113163.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1817094379.00000000006B2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1819838646.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1781183252.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1757476953.00000000006A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://deoci.biz/ |
Source: armsvc.exe, 00000001.00000003.1790247195.00000000006AA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://dwrqljrr.biz/J |
Source: armsvc.exe, 00000001.00000003.1915528007.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://gnqgo.biz/ |
Source: armsvc.exe, 00000001.00000003.1665217708.00000000006A9000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1664959944.00000000006A2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ifsaia.biz/2/~ |
Source: armsvc.exe, 00000001.00000003.1915528007.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://jhvzpcfg.biz/ |
Source: armsvc.exe, 00000001.00000003.1883216416.00000000006A3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1850328223.00000000006A6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://jpskm.biz/h |
Source: armsvc.exe, 00000001.00000003.1883216416.00000000006A3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://lrxdmhrr.biz/ |
Source: armsvc.exe, 00000001.00000003.1737461235.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1750002483.00000000006A8000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1790247195.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1149701624.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1690852057.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1643910161.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1719723025.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1675473221.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1883216416.00000000006A3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1774465553.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1838113163.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1729481996.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1384298264.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1673962751.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1625467325.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1665217708.00000000006A9000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1915528007.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1664959944.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://npukfztj.biz/ |
Source: armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1838113163.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1819838646.00000000006AB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://nqwjmb.biz//J |
Source: DHL Original Shipment Document PDF.exe, 00000000.00000002.1077140822.0000000000C48000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1074663290.0000000000692000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://pywolwnvd.biz/ |
Source: armsvc.exe, 00000001.00000003.1690852057.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1719723025.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1675473221.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1673962751.00000000006AA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://saytjshyf.biz/~ |
Source: armsvc.exe, 00000001.00000003.1105877749.0000000000692000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1091858221.0000000000692000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ssbzmoy.biz/ |
Source: armsvc.exe, 00000001.00000003.1737461235.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1750002483.00000000006A8000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1790247195.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1883216416.00000000006A3000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1774465553.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1838113163.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1729481996.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1819838646.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1781183252.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1757476953.00000000006A5000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1850328223.00000000006A6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://tbjrpv.biz/ |
Source: armsvc.exe, 00000001.00000003.1690852057.00000000006AA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://vcddkls.biz/0 |
Source: armsvc.exe, 00000001.00000003.1720118872.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.fwiwk.biz/ |
Source: armsvc.exe, armsvc.exe, 00000001.00000003.1705942558.0000000002340000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.fwiwk.biz/?ts=fENsZWFuUGVwcGVybWludEJsYWNrfHw1Y2U4NHxidWNrZXQwNzB8fHx8fHw2N2NmZjMxZDZlYj |
Source: armsvc.exe, 00000001.00000003.1718994307.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1817094379.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1789357573.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1780565921.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1819838646.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1736808501.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1838113163.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1756391366.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1708208096.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1728702326.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1718994307.00000000006F6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1808646588.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1878704536.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1798481226.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1708208096.00000000006F6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1914259949.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1773645573.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1850328223.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1707538342.00000000006F6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.fwiwk.biz/u?usid=20&utid=15161491447 |
Source: armsvc.exe, 00000001.00000003.1729846861.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1720118872.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1737897252.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.fwiwk.biz/u?usid=20&utid=15161491447J |
Source: armsvc.exe, 00000001.00000003.1149701624.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1131899721.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/ |
Source: armsvc.exe, 00000001.00000003.1149701624.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1131899721.0000000000685000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1384298264.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/5 |
Source: armsvc.exe, 00000001.00000003.1131899721.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/8w |
Source: armsvc.exe, 00000001.00000003.1131899721.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/:w |
Source: armsvc.exe, 00000001.00000003.1126429988.0000000002060000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/?ts=fENsZWFuUGVwcGVybWludEJsYWNrfHw1Y2U4NHxidWNrZXQwMTd8fHx8fHw2N2NmZjJlMzVk |
Source: armsvc.exe, 00000001.00000003.1131349976.0000000002200000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1131899721.000000000067D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/?ts=fENsZWFuUGVwcGVybWludEJsYWNrfHw1Y2U4NHxidWNrZXQwMTd8fHx8fHw2N2NmZjJlNDI1 |
Source: armsvc.exe, 00000001.00000003.1131899721.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/dkqtpnrkho?usid=20&utid=15161478388 |
Source: armsvc.exe, 00000001.00000003.1131899721.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/io?usid=20&utid=15161478105 |
Source: armsvc.exe, 00000001.00000003.1149701624.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1131899721.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz/io?usid=20&utid=15161478105% |
Source: armsvc.exe, 00000001.00000003.1149701624.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1131899721.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww12.przvgke.biz3c-4f66-939b-29faacb309944 |
Source: armsvc.exe, 00000001.00000003.1737461235.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1750002483.00000000006A8000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1790247195.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1799890431.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1719723025.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1774465553.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1729481996.00000000006AB000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1781183252.00000000006AA000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1757476953.00000000006A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww7.fwiwk.biz/ |
Source: armsvc.exe, 00000001.00000003.1720118872.0000000000685000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww7.fwiwk.biz/f |
Source: armsvc.exe, 00000001.00000003.1720118872.0000000000694000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1849353587.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1773645573.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1850328223.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1737897252.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww7.fwiwk.biz/xfnijcvy?usid=20&utid=15161491680 |
Source: armsvc.exe, 00000001.00000003.1720118872.0000000000694000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ww7.fwiwk.bizurity=Impersonation |
Source: yrC1hsBFkVzDRlK9HaXIw3.exe, 00000023.00000002.2341517674.00000000057F6000.00000040.80000000.00040000.00000000.sdmp | String found in binary or memory: http://www.agistaking.xyz |
Source: yrC1hsBFkVzDRlK9HaXIw3.exe, 00000023.00000002.2341517674.00000000057F6000.00000040.80000000.00040000.00000000.sdmp | String found in binary or memory: http://www.agistaking.xyz/bguu/ |
Source: armsvc.exe, 00000001.00000003.1539084492.0000000002030000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: armsvc.exe, 00000001.00000003.1643910161.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1665217708.00000000006A9000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1664959944.00000000006A2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://xlfhhhm.biz/ |
Source: sppsvc.exe.1.dr | String found in binary or memory: http://xml.org/sax/properties/lexical-handler&<>"'SelectionLanguageXPathSelectio |
Source: armsvc.exe, 00000001.00000003.1807189421.00000000006A2000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1816082671.00000000006A4000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1819838646.00000000006AB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ytctnunms.biz/ |
Source: mfpmp.exe, 00000012.00000003.1475056977.000000000807D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ac.ecosia.org?q= |
Source: mfpmp.exe, 00000012.00000003.1475056977.000000000807D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: mfpmp.exe, 00000012.00000003.1475056977.000000000807D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: mfpmp.exe, 00000012.00000003.1475056977.000000000807D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: Acrobat.exe.1.dr | String found in binary or memory: https://clients2.google.com/service/update2/crxBrowser |
Source: armsvc.exe, 00000001.00000003.1606598702.0000000002030000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://clients2.google.com/service/update2/crxFailed |
Source: armsvc.exe, 00000001.00000003.1607680423.0000000002030000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1608041436.0000000002030000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://clients2.google.com/service/update2/crxHKEY_LOCAL_MACHINE |
Source: mfpmp.exe, 00000012.00000003.1475056977.000000000807D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: mfpmp.exe, 00000012.00000003.1475056977.000000000807D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtabv20 |
Source: mfpmp.exe, 00000012.00000003.1475056977.000000000807D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: armsvc.exe, armsvc.exe, 00000001.00000003.1705701568.0000000000950000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1131349976.0000000002200000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1125570259.0000000002090000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1705942558.0000000002340000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1126429988.0000000002060000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1131280233.0000000001F90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://euob.seaskydvd.com/sxp/i/224f85302aa2b6ec30aac9a85da2cbf9.js |
Source: mfpmp.exe, 00000012.00000003.1475056977.000000000807D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gemini.google.com/app?q= |
Source: mfpmp.exe, 00000012.00000002.2307560381.0000000003369000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_authorize.srf?client_id=00000000480728C5&scope=service::ssl.live.com: |
Source: mfpmp.exe, 00000012.00000002.2307560381.0000000003343000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_authorize.srfclient_id=00000000480728C5&scope=service::ssl.live.com:: |
Source: mfpmp.exe, 00000012.00000003.1468432776.000000000805E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_authorize.srfhttps://login.live.com/oauth20_desktop.srfhttps://login. |
Source: mfpmp.exe, 00000012.00000002.2307560381.0000000003369000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033 |
Source: mfpmp.exe, 00000012.00000002.2307560381.0000000003343000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srflc=10333z |
Source: mfpmp.exe, 00000012.00000002.2307560381.0000000003369000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_logout.srf?client_id=00000000480728C5&redirect_uri=https://login.live |
Source: mfpmp.exe, 00000012.00000002.2307560381.0000000003369000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_logout.srfclient_id=00000000480728C5&redirect_uri=https://login.live. |
Source: armsvc.exe, armsvc.exe, 00000001.00000003.1705701568.0000000000950000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1705942558.0000000002340000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://parking3.parklogic.com/page/enhance.js?pcId=12&domain=fwiwk.biz |
Source: armsvc.exe, 00000001.00000003.1131349976.0000000002200000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1125570259.0000000002090000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1126429988.0000000002060000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1131280233.0000000001F90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://parking3.parklogic.com/page/enhance.js?pcId=12&domain=przvgke.biz |
Source: armsvc.exe, 00000001.00000003.1131349976.0000000002200000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1131899721.000000000067D000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1126429988.0000000002060000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://pcnatrk.net/munin/a/tr/click |
Source: armsvc.exe, 00000001.00000003.1705942558.0000000002340000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1720118872.000000000067D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://trkpcna.net/munin/a/tr/click |
Source: mfpmp.exe, 00000012.00000003.1475056977.000000000807D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.ecosia.org/newtab/v20 |
Source: armsvc.exe, 00000001.00000003.1718994307.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1789357573.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1780565921.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1736808501.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1756391366.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1716814627.0000000002380000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1751358520.0000000000661000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1728702326.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1716596432.0000000000950000.00000004.00001000.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1738423204.0000000000660000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1808646588.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1798481226.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, armsvc.exe, 00000001.00000003.1773645573.00000000006E6000.00000004.00000020.00020000.00000000.sdmp, mfpmp.exe, 00000012.00000002.2346885096.00000000065C0000.00000004.00000800.00020000.00000000.sdmp, mfpmp.exe, 00000012.00000002.2341935250.0000000004608000.00000004.10000000.00040000.00000000.sdmp, yrC1hsBFkVzDRlK9HaXIw3.exe, 00000023.00000002.2337000376.0000000003A78000.00000004.00000001.00040000.00000000.sdmp | String found in binary or memory: https://www.google.com |
Source: mfpmp.exe, 00000012.00000003.1475056977.000000000807D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_alldp.ico |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_0040E6A0 | 0_2_0040E6A0 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_0042D975 | 0_2_0042D975 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_004221C5 | 0_2_004221C5 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_004362D2 | 0_2_004362D2 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_004803DA | 0_2_004803DA |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_0043242E | 0_2_0043242E |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_004225FA | 0_2_004225FA |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_0045E616 | 0_2_0045E616 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_004166E1 | 0_2_004166E1 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_0043878F | 0_2_0043878F |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00436844 | 0_2_00436844 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00480857 | 0_2_00480857 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00418808 | 0_2_00418808 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00468889 | 0_2_00468889 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_0042CB21 | 0_2_0042CB21 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00524CC8 | 0_2_00524CC8 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00436DB6 | 0_2_00436DB6 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00416F9E | 0_2_00416F9E |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00413030 | 0_2_00413030 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_0042F1D9 | 0_2_0042F1D9 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00423187 | 0_2_00423187 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00401287 | 0_2_00401287 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00421484 | 0_2_00421484 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00415520 | 0_2_00415520 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00427696 | 0_2_00427696 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00415760 | 0_2_00415760 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00421978 | 0_2_00421978 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00439AB5 | 0_2_00439AB5 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_0040FCE0 | 0_2_0040FCE0 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00487DDB | 0_2_00487DDB |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00421D90 | 0_2_00421D90 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_0042BDA6 | 0_2_0042BDA6 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_0040DF00 | 0_2_0040DF00 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00413FE0 | 0_2_00413FE0 |
Source: C:\Users\user\Desktop\DHL Original Shipment Document PDF.exe | Code function: 0_2_00CD52A8 | 0_2_00CD52A8 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00950108 | 1_3_00950108 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00950108 | 1_3_00950108 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00950108 | 1_3_00950108 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00950108 | 1_3_00950108 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_0096669D | 1_3_0096669D |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_0096669D | 1_3_0096669D |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_0096669D | 1_3_0096669D |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_009662F6 | 1_3_009662F6 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_009662F6 | 1_3_009662F6 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_009662F6 | 1_3_009662F6 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00966AE1 | 1_3_00966AE1 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00966AE1 | 1_3_00966AE1 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00966AE1 | 1_3_00966AE1 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00965C93 | 1_3_00965C93 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_0096669D | 1_3_0096669D |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_0096669D | 1_3_0096669D |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_0096669D | 1_3_0096669D |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_009662F6 | 1_3_009662F6 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_009662F6 | 1_3_009662F6 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_009662F6 | 1_3_009662F6 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00966AE1 | 1_3_00966AE1 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00966AE1 | 1_3_00966AE1 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00966AE1 | 1_3_00966AE1 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00965C93 | 1_3_00965C93 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00965F9F | 1_3_00965F9F |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_0096669D | 1_3_0096669D |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_0096669D | 1_3_0096669D |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_0096669D | 1_3_0096669D |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00966EA7 | 1_3_00966EA7 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_009662F6 | 1_3_009662F6 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_009662F6 | 1_3_009662F6 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_009662F6 | 1_3_009662F6 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00966AE1 | 1_3_00966AE1 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00966AE1 | 1_3_00966AE1 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00966AE1 | 1_3_00966AE1 |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Code function: 1_3_00965C93 | 1_3_00965C93 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_00418BE3 | 4_2_00418BE3 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_004028C0 | 4_2_004028C0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0042F163 | 4_2_0042F163 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_004031C0 | 4_2_004031C0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_004011D0 | 4_2_004011D0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_00410430 | 4_2_00410430 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_00410433 | 4_2_00410433 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_00402493 | 4_2_00402493 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_004024A0 | 4_2_004024A0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_00402D5D | 4_2_00402D5D |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_00402D60 | 4_2_00402D60 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_00404569 | 4_2_00404569 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_00416DEE | 4_2_00416DEE |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_00416DF3 | 4_2_00416DF3 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_00410653 | 4_2_00410653 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0040E629 | 4_2_0040E629 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0040E633 | 4_2_0040E633 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0040475E | 4_2_0040475E |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0040E77E | 4_2_0040E77E |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0040E7CC | 4_2_0040E7CC |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0040E783 | 4_2_0040E783 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FA352 | 4_2_034FA352 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0344E3F0 | 4_2_0344E3F0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_035003E6 | 4_2_035003E6 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034E0274 | 4_2_034E0274 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034C02C0 | 4_2_034C02C0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034C8158 | 4_2_034C8158 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03430100 | 4_2_03430100 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034DA118 | 4_2_034DA118 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F81CC | 4_2_034F81CC |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F41A2 | 4_2_034F41A2 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_035001AA | 4_2_035001AA |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034D2000 | 4_2_034D2000 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03464750 | 4_2_03464750 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03440770 | 4_2_03440770 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0343C7C0 | 4_2_0343C7C0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0345C6E0 | 4_2_0345C6E0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03440535 | 4_2_03440535 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03500591 | 4_2_03500591 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F2446 | 4_2_034F2446 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034E4420 | 4_2_034E4420 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034EE4F6 | 4_2_034EE4F6 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FAB40 | 4_2_034FAB40 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F6BD7 | 4_2_034F6BD7 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0343EA80 | 4_2_0343EA80 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03456962 | 4_2_03456962 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034429A0 | 4_2_034429A0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0350A9A6 | 4_2_0350A9A6 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0344A840 | 4_2_0344A840 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03442840 | 4_2_03442840 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0346E8F0 | 4_2_0346E8F0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034268B8 | 4_2_034268B8 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034B4F40 | 4_2_034B4F40 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03482F28 | 4_2_03482F28 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03460F30 | 4_2_03460F30 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034E2F30 | 4_2_034E2F30 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03432FC8 | 4_2_03432FC8 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0344CFE0 | 4_2_0344CFE0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034BEFA0 | 4_2_034BEFA0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03440E59 | 4_2_03440E59 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FEE26 | 4_2_034FEE26 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FEEDB | 4_2_034FEEDB |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03452E90 | 4_2_03452E90 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FCE93 | 4_2_034FCE93 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0344AD00 | 4_2_0344AD00 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034DCD1F | 4_2_034DCD1F |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0343ADE0 | 4_2_0343ADE0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03458DBF | 4_2_03458DBF |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03440C00 | 4_2_03440C00 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03430CF2 | 4_2_03430CF2 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034E0CB5 | 4_2_034E0CB5 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0342D34C | 4_2_0342D34C |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F132D | 4_2_034F132D |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0348739A | 4_2_0348739A |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0345B2C0 | 4_2_0345B2C0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034E12ED | 4_2_034E12ED |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034452A0 | 4_2_034452A0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0347516C | 4_2_0347516C |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0342F172 | 4_2_0342F172 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0350B16B | 4_2_0350B16B |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0344B1B0 | 4_2_0344B1B0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034EF0CC | 4_2_034EF0CC |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F70E9 | 4_2_034F70E9 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FF0E0 | 4_2_034FF0E0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FF7B0 | 4_2_034FF7B0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03485630 | 4_2_03485630 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F16CC | 4_2_034F16CC |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F7571 | 4_2_034F7571 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_035095C3 | 4_2_035095C3 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034DD5B0 | 4_2_034DD5B0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03431460 | 4_2_03431460 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FF43F | 4_2_034FF43F |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FFB76 | 4_2_034FFB76 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034B5BF0 | 4_2_034B5BF0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0347DBF9 | 4_2_0347DBF9 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0345FB80 | 4_2_0345FB80 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FFA49 | 4_2_034FFA49 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F7A46 | 4_2_034F7A46 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034B3A6C | 4_2_034B3A6C |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034EDAC6 | 4_2_034EDAC6 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034DDAAC | 4_2_034DDAAC |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03485AA0 | 4_2_03485AA0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034E1AA3 | 4_2_034E1AA3 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03449950 | 4_2_03449950 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0345B950 | 4_2_0345B950 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034D5910 | 4_2_034D5910 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034AD800 | 4_2_034AD800 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034438E0 | 4_2_034438E0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FFF09 | 4_2_034FFF09 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03403FD2 | 4_2_03403FD2 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03403FD5 | 4_2_03403FD5 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03441F92 | 4_2_03441F92 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FFFB1 | 4_2_034FFFB1 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_03449EB0 | 4_2_03449EB0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F1D5A | 4_2_034F1D5A |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034F7D73 | 4_2_034F7D73 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_0345FDC0 | 4_2_0345FDC0 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034B9C32 | 4_2_034B9C32 |
Source: C:\Windows\SysWOW64\svchost.exe | Code function: 4_2_034FFCF2 | 4_2_034FFCF2 |
Source: DHL Original Shipment Document PDF.exe | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: armsvc.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: alg.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVClient.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: DiagnosticsHub.StandardCollector.Service.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zFM.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevated_tracing_service.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zG.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcrobatInfo.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: acrobat_sl.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroBroker.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: updater.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: maintenanceservice.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe0.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msdtc.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe0.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroTextExtractor.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msiexec.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: PerceptionSimulationService.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: perfhost.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Locator.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: FXSSVC.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe0.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ADelRCP.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ADNotificationManager.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AdobeCollabSync.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: WCChromeNativeMessagingHost.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MsSense.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SensorDataService.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: CRLogTransport.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SgrmBroker.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: snmptrap.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: CRWindowsClientService.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Spectrum.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Eula.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: sppsvc.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ssh-agent.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: LogTransport2.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: adobe_licensing_wf_acro.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: adobe_licensing_wf_helper_acro.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 32BitMAPIBroker.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 64BitMAPIBroker.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MSRMSPIBroker.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: TieringEngineService.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: FullTrustNotifier.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AgentService.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ShowAppPickerForPDF.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: vds.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe0.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: VSSVC.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: wbengine.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: WmiApSrv.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: wmpnetwk.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: appvcleaner.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVShNotify.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: IntegratedOffice.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MavInject32.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SearchIndexer.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: OfficeC2RClient.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: officesvcmgr.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7z.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: chrome_pwa_launcher.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: DHL Original Shipment Document PDF.exe | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: armsvc.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: alg.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVClient.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: DiagnosticsHub.StandardCollector.Service.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zFM.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevated_tracing_service.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zG.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcrobatInfo.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: acrobat_sl.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroBroker.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: updater.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: maintenanceservice.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe0.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msdtc.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe0.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroTextExtractor.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msiexec.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: PerceptionSimulationService.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: perfhost.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Locator.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: FXSSVC.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe0.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ADelRCP.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ADNotificationManager.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AdobeCollabSync.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: WCChromeNativeMessagingHost.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MsSense.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SensorDataService.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: CRLogTransport.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SgrmBroker.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: snmptrap.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: CRWindowsClientService.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Spectrum.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Eula.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: sppsvc.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ssh-agent.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: LogTransport2.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: adobe_licensing_wf_acro.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: adobe_licensing_wf_helper_acro.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 32BitMAPIBroker.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 64BitMAPIBroker.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MSRMSPIBroker.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: TieringEngineService.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: FullTrustNotifier.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AgentService.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ShowAppPickerForPDF.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: vds.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe0.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: VSSVC.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: wbengine.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: WmiApSrv.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: wmpnetwk.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: appvcleaner.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVShNotify.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: IntegratedOffice.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MavInject32.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SearchIndexer.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: OfficeC2RClient.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: officesvcmgr.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7z.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: chrome_pwa_launcher.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |