Source: JUST1F1.exe, 00000006.00000002.990481761.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: JUST1F1.exe, 00000006.00000002.990481761.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: http://DynDns.comDynDNS |
Source: JUST1F1.exe, 00000006.00000002.990481761.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: http://RmfrFmh6Ec0Y1.com |
Source: JUST1F1.exe, 00000006.00000002.990481761.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: http://RmfrFmh6Ec0Y1.comLE |
Source: JUST1F1.exe, 00000006.00000002.990692781.000000000345C000.00000004.00000001.sdmp | String found in binary or memory: http://cacerts.geotrust.com/GeoTrustRSACA2018.crt0 |
Source: JUST1F1.exe, 00000006.00000002.990692781.000000000345C000.00000004.00000001.sdmp | String found in binary or memory: http://cdp.geotrust.com/GeoTrustRSACA2018.crl0L |
Source: JUST1F1.exe, 00000006.00000002.990692781.000000000345C000.00000004.00000001.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0= |
Source: JUST1F1.exe, 00000006.00000002.990692781.000000000345C000.00000004.00000001.sdmp | String found in binary or memory: http://ocsp.digicert.com0B |
Source: JUST1F1.exe, 00000006.00000002.990481761.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: http://qphjuU.com |
Source: JUST1F1.exe, 00000006.00000002.990692781.000000000345C000.00000004.00000001.sdmp | String found in binary or memory: http://status.geotrust.com0= |
Source: JUST1F1.exe, 00000006.00000002.990692781.000000000345C000.00000004.00000001.sdmp | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: JUST1F1.exe, 00000005.00000002.675383386.0000000004481000.00000004.00000001.sdmp, JUST1F1.exe, 00000006.00000002.989247161.0000000000402000.00000040.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: JUST1F1.exe, 00000006.00000002.990481761.0000000003331000.00000004.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: C:\Windows\SysWOW64\unarchiver.exe | Code function: 0_2_018102A8 |
Source: C:\Windows\SysWOW64\unarchiver.exe | Code function: 0_2_01810299 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_013228A4 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_01336484 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_02FA1074 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_02FAA608 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_02FA5BF2 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_02FA17B0 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_02FA17A0 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_02FA1478 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_02FA1468 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_02FA4C50 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_02FA844B |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 5_2_02FA4C40 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_015D1D00 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_0543E138 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_0543D9E0 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_0543B7A0 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_05438C40 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_05430A98 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_05438BE0 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_05DDE9C8 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_05DD91B0 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_05DDCDA4 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_05DDE570 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_05DD3F11 |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Code function: 6_2_05DD5A10 |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\jwzcmshk.kmg\JUST1F1.exe | Process information set: NOOPENFILEERRORBOX |
Source: JUST1F1.exe, 00000006.00000002.989813861.0000000001248000.00000004.00000020.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllSUY6 |
Source: JUST1F1.exe, 00000005.00000002.674621864.0000000003481000.00000004.00000001.sdmp | Binary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: JUST1F1.exe, 00000006.00000002.992224555.0000000005640000.00000002.00000001.sdmp | Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: JUST1F1.exe, 00000005.00000002.674621864.0000000003481000.00000004.00000001.sdmp | Binary or memory string: vmware |
Source: JUST1F1.exe, 00000006.00000002.992224555.0000000005640000.00000002.00000001.sdmp | Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: JUST1F1.exe, 00000006.00000002.992224555.0000000005640000.00000002.00000001.sdmp | Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: JUST1F1.exe, 00000005.00000002.674621864.0000000003481000.00000004.00000001.sdmp | Binary or memory string: VMware SVGA II |
Source: JUST1F1.exe, 00000006.00000002.989795749.0000000001225000.00000004.00000020.sdmp | Binary or memory string: Hyper-V RAW" |
Source: JUST1F1.exe, 00000005.00000002.674029983.000000000140B000.00000004.00000020.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: JUST1F1.exe, 00000005.00000002.674621864.0000000003481000.00000004.00000001.sdmp | Binary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools |
Source: JUST1F1.exe, 00000006.00000002.992224555.0000000005640000.00000002.00000001.sdmp | Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |