Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.108.38.112 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.108.38.112 |
Source: unknown | TCP traffic detected without corresponding DNS query: 205.185.216.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.108.60.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.108.60.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.108.60.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.80.21.45 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 205.185.216.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.27.233.126 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.27.233.126 |
Source: unknown | TCP traffic detected without corresponding DNS query: 205.185.216.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.83.66.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.27.233.126 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: Proforma Invoice with Bank Details_pdf.exe, Proforma Invoice with Bank Details_pdf.exe, 00000000.00000002.209201167.0000000000C66000.00000004.00020000.sdmp, MSBuild.exe, 00000003.00000002.469545862.0000000000402000.00000040.00000001.sdmp | String found in binary or memory: http://127.0.0.1: |
Source: MSBuild.exe, 00000003.00000002.474100533.0000000002DA4000.00000004.00000001.sdmp | String found in binary or memory: http://AAETsHFcmz5EiUda3E.net |
Source: MSBuild.exe, 00000003.00000002.473614554.0000000002CCE000.00000004.00000001.sdmp | String found in binary or memory: http://AAETsHFcmz5EiUda3E.net0 |
Source: Proforma Invoice with Bank Details_pdf.exe, Proforma Invoice with Bank Details_pdf.exe, 00000000.00000002.209201167.0000000000C66000.00000004.00020000.sdmp, MSBuild.exe, 00000003.00000002.469545862.0000000000402000.00000040.00000001.sdmp | String found in binary or memory: https://api.telegram.org/bot%telegramapi%/ |
Source: Proforma Invoice with Bank Details_pdf.exe | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/ |
Source: Proforma Invoice with Bank Details_pdf.exe, MSBuild.exe, 00000003.00000002.469545862.0000000000402000.00000040.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: Proforma Invoice with Bank Details_pdf.exe, 00000000.00000002.209201167.0000000000C66000.00000004.00020000.sdmp, MSBuild.exe, 00000003.00000002.469545862.0000000000402000.00000040.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/U |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C550D1 | 0_2_00C550D1 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C56845 | 0_2_00C56845 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C5584D | 0_2_00C5584D |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C4A1A4 | 0_2_00C4A1A4 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C48283 | 0_2_00C48283 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C493F9 | 0_2_00C493F9 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C48B8F | 0_2_00C48B8F |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C4E3B9 | 0_2_00C4E3B9 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C54B61 | 0_2_00C54B61 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C545F1 | 0_2_00C545F1 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C48FC4 | 0_2_00C48FC4 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C47F60 | 0_2_00C47F60 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C48777 | 0_2_00C48777 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FADCB9 | 3_2_04FADCB9 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA7AA0 | 3_2_04FA7AA0 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA9498 | 3_2_04FA9498 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FACC4F | 3_2_04FACC4F |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA821F | 3_2_04FA821F |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FAEC1F | 3_2_04FAEC1F |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04F90006 | 3_2_04F90006 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA31F8 | 3_2_04FA31F8 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA3588 | 3_2_04FA3588 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA1568 | 3_2_04FA1568 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA713E | 3_2_04FA713E |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA9120 | 3_2_04FA9120 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA1D20 | 3_2_04FA1D20 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA3588 | 3_2_04FA3588 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA56E3 | 3_2_04FA56E3 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA28C8 | 3_2_04FA28C8 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA28BA | 3_2_04FA28BA |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA58BD | 3_2_04FA58BD |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FAA4B2 | 3_2_04FAA4B2 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA2099 | 3_2_04FA2099 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA7A8F | 3_2_04FA7A8F |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA564A | 3_2_04FA564A |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA9E18 | 3_2_04FA9E18 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FAB7F8 | 3_2_04FAB7F8 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA49CE | 3_2_04FA49CE |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA85C1 | 3_2_04FA85C1 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA7BA8 | 3_2_04FA7BA8 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA7F88 | 3_2_04FA7F88 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA6B82 | 3_2_04FA6B82 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FACC4F | 3_2_04FACC4F |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA577C | 3_2_04FA577C |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA1558 | 3_2_04FA1558 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA6D45 | 3_2_04FA6D45 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA2136 | 3_2_04FA2136 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_04FA1D10 | 3_2_04FA1D10 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F307F0 | 3_2_05F307F0 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F359C8 | 3_2_05F359C8 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F35370 | 3_2_05F35370 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F33740 | 3_2_05F33740 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F30D10 | 3_2_05F30D10 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F37710 | 3_2_05F37710 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F31CC0 | 3_2_05F31CC0 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F38658 | 3_2_05F38658 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F37E08 | 3_2_05F37E08 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F37DF8 | 3_2_05F37DF8 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F307D3 | 3_2_05F307D3 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F30DCD | 3_2_05F30DCD |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F363CC | 3_2_05F363CC |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F30DBB | 3_2_05F30DBB |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F33731 | 3_2_05F33731 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F31115 | 3_2_05F31115 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F30D01 | 3_2_05F30D01 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F37700 | 3_2_05F37700 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F308D6 | 3_2_05F308D6 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F31CB3 | 3_2_05F31CB3 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F372BC | 3_2_05F372BC |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F31EA3 | 3_2_05F31EA3 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F30E93 | 3_2_05F30E93 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F37E87 | 3_2_05F37E87 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F30E6A | 3_2_05F30E6A |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F38648 | 3_2_05F38648 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F30A2A | 3_2_05F30A2A |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F32414 | 3_2_05F32414 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F4A148 | 3_2_05F4A148 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F4AED0 | 3_2_05F4AED0 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F4EAD0 | 3_2_05F4EAD0 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F4BE50 | 3_2_05F4BE50 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F4B250 | 3_2_05F4B250 |
Source: 3.2.MSBuild.exe.400000.0.unpack, gtu.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 3.2.MSBuild.exe.400000.0.unpack, gtu.cs | Cryptographic APIs: 'CreateDecryptor', 'TransformFinalBlock' |
Source: 3.2.MSBuild.exe.400000.0.unpack, gtu.cs | Cryptographic APIs: 'CreateDecryptor', 'TransformBlock' |
Source: 3.2.MSBuild.exe.400000.0.unpack, DPAPI.cs | Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor' |
Source: 3.2.MSBuild.exe.400000.0.unpack, DPAPI.cs | Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor' |
Source: unknown | Process created: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe 'C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe' | |
Source: unknown | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c schtasks /Create /TN name /XML 'C:\Users\user\AppData\Local\Temp\eb880290d3c747809c5fd1c3af592ae7.xml' | |
Source: unknown | Process created: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | |
Source: unknown | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /Create /TN name /XML 'C:\Users\user\AppData\Local\Temp\eb880290d3c747809c5fd1c3af592ae7.xml' | |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c schtasks /Create /TN name /XML 'C:\Users\user\AppData\Local\Temp\eb880290d3c747809c5fd1c3af592ae7.xml' | Jump to behavior |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Process created: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /Create /TN name /XML 'C:\Users\user\AppData\Local\Temp\eb880290d3c747809c5fd1c3af592ae7.xml' | Jump to behavior |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C5216C EncodePointer,EncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, | 0_2_00C5216C |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C66924 push ebx; iretd | 0_2_00C66925 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C662AC pushad ; iretd | 0_2_00C662AD |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C66B0A push ecx; ret | 0_2_00C66B0B |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C6A41A push edx; retf | 0_2_00C6A41E |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C60554 push eax; ret | 0_2_00C605B9 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C45665 push ecx; ret | 0_2_00C45678 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C60608 push eax; ret | 0_2_00C605B9 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C4AF95 push ecx; ret | 0_2_00C4AFA8 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05893FB7 push cs; retf | 3_2_05893FCF |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05893F43 push cs; retf | 3_2_05893F5B |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05893ECF push cs; retf | 3_2_05893EE7 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F341F6 push ebx; iretd | 3_2_05F341FF |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F315E9 push 0000005Dh; ret | 3_2_05F315EB |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F3012A push 69FFFFFFh; ret | 3_2_05F30139 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F41722 push 08F2E872h; retf | 3_2_05F41728 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Code function: 3_2_05F41712 push 0902E872h; retf | 3_2_05F41718 |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep count: 338 > 30 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -10140000s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -149530s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -89673s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -149300s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -179154s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -59780s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -39626s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -39374s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -39250s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -489450s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep count: 32 > 30 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -334016s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -39126s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -487875s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep count: 35 > 30 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -366940s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep count: 33 > 30 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -644028s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -199215s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -271362s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -117192s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -371089s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -58737s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -31500s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -39124s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -39000s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -77812s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -31689s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -96955s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -53045s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -58170s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -58218s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -52810s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe TID: 7084 | Thread sleep time: -31830s >= -30000s | Jump to behavior |
Source: MSBuild.exe, 00000003.00000002.475746937.00000000054B0000.00000002.00000001.sdmp | Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: MSBuild.exe, 00000003.00000003.315248335.0000000000CCF000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW |
Source: MSBuild.exe, 00000003.00000002.475746937.00000000054B0000.00000002.00000001.sdmp | Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: MSBuild.exe, 00000003.00000003.315248335.0000000000CCF000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dlll |
Source: MSBuild.exe, 00000003.00000002.475746937.00000000054B0000.00000002.00000001.sdmp | Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: MSBuild.exe, 00000003.00000002.475746937.00000000054B0000.00000002.00000001.sdmp | Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C5216C EncodePointer,EncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, | 0_2_00C5216C |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C5216C EncodePointer,EncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, | 0_2_00C5216C |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C5216C EncodePointer,EncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, | 0_2_00C5216C |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C41970 mov eax, dword ptr fs:[00000030h] | 0_2_00C41970 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C41970 mov eax, dword ptr fs:[00000030h] | 0_2_00C41970 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C654C7 mov eax, dword ptr fs:[00000030h] | 0_2_00C654C7 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C61CC2 mov eax, dword ptr fs:[00000030h] | 0_2_00C61CC2 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C65567 mov eax, dword ptr fs:[00000030h] | 0_2_00C65567 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: 0_2_00C65504 mov eax, dword ptr fs:[00000030h] | 0_2_00C65504 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeW,_memmove,_memmove,_memmove,InterlockedDecrement,_free,_free,_free,_free,_free,_free,_free,_free,_free,InterlockedDecrement, | 0_2_00C44897 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free, | 0_2_00C50BA1 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson, | 0_2_00C4B35D |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, | 0_2_00C524CA |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo, | 0_2_00C515AE |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: EnumSystemLocalesEx, | 0_2_00C4F54A |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: GetLocaleInfoEx, | 0_2_00C4F560 |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free, | 0_2_00C50FAA |
Source: C:\Users\user\Desktop\Proforma Invoice with Bank Details_pdf.exe | Code function: GetLocaleInfoEx,__wcsnicmp,_TestDefaultCountry,_TestDefaultCountry,__invoke_watson,__invoke_watson, | 0_2_00C5276E |
Source: Yara match | File source: 00000003.00000002.473024653.0000000002C01000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.209201167.0000000000C66000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.473614554.0000000002CCE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.469545862.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.474100533.0000000002DA4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: MSBuild.exe PID: 6744, type: MEMORY |
Source: Yara match | File source: Process Memory Space: Proforma Invoice with Bank Details_pdf.exe PID: 6672, type: MEMORY |
Source: Yara match | File source: 0.2.Proforma Invoice with Bank Details_pdf.exe.c40000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000003.00000002.473024653.0000000002C01000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.209201167.0000000000C66000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.473614554.0000000002CCE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.469545862.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.474100533.0000000002DA4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: MSBuild.exe PID: 6744, type: MEMORY |
Source: Yara match | File source: Process Memory Space: Proforma Invoice with Bank Details_pdf.exe PID: 6672, type: MEMORY |
Source: Yara match | File source: 0.2.Proforma Invoice with Bank Details_pdf.exe.c40000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE |