Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.53.167.113 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.17.179.193 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 84.53.167.113 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.17.179.193 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.17.179.193 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.129.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 186.64.119.165 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 186.64.119.165 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 186.64.119.165 |
Source: MSBuild.exe, 00000003.00000002.575561117.0000000003401000.00000004.00000001.sdmp |
String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: MSBuild.exe, 00000003.00000002.575561117.0000000003401000.00000004.00000001.sdmp |
String found in binary or memory: http://DynDns.comDynDNS |
Source: MSBuild.exe, 00000003.00000002.578383711.0000000003691000.00000004.00000001.sdmp, MSBuild.exe, 00000003.00000002.575713024.000000000343C000.00000004.00000001.sdmp, MSBuild.exe, 00000003.00000002.578974533.00000000036FC000.00000004.00000001.sdmp, MSBuild.exe, 00000003.00000002.579011179.0000000003701000.00000004.00000001.sdmp |
String found in binary or memory: http://cV9LNZgDQeR7CK6z.org |
Source: MSBuild.exe, 00000003.00000002.578692738.00000000036D2000.00000004.00000001.sdmp |
String found in binary or memory: http://chestronic.com |
Source: MSBuild.exe, 00000003.00000002.578757614.00000000036D8000.00000004.00000001.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04 |
Source: MSBuild.exe, 00000003.00000002.588294433.0000000006600000.00000004.00000001.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: MSBuild.exe, 00000003.00000003.450505714.000000000661F000.00000004.00000001.sdmp |
String found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q |
Source: MSBuild.exe, 00000003.00000002.578757614.00000000036D8000.00000004.00000001.sdmp |
String found in binary or memory: http://crl.comodoca.com/cPanelIncCertificationAuthority.crl0 |
Source: MSBuild.exe, 00000003.00000002.578692738.00000000036D2000.00000004.00000001.sdmp |
String found in binary or memory: http://mail.chestronic.com |
Source: MSBuild.exe, 00000003.00000003.450505714.000000000661F000.00000004.00000001.sdmp |
String found in binary or memory: http://ocsp.comodoca.com0 |
Source: Statement of Account.exe, 00000000.00000002.227700296.0000000002B01000.00000004.00000001.sdmp, MSBuild.exe, 00000003.00000002.575561117.0000000003401000.00000004.00000001.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: MSBuild.exe, 00000003.00000002.575561117.0000000003401000.00000004.00000001.sdmp |
String found in binary or memory: http://sjSmfS.com |
Source: MSBuild.exe, 00000003.00000002.575561117.0000000003401000.00000004.00000001.sdmp |
String found in binary or memory: https://api.ipify.org |
Source: MSBuild.exe, 00000003.00000002.575561117.0000000003401000.00000004.00000001.sdmp |
String found in binary or memory: https://api.ipify.org/ |
Source: MSBuild.exe, 00000003.00000002.575561117.0000000003401000.00000004.00000001.sdmp |
String found in binary or memory: https://api.ipify.orgGETMozilla/5.0 |
Source: Statement of Account.exe, 00000000.00000002.230197757.0000000003B5F000.00000004.00000001.sdmp, MSBuild.exe, 00000003.00000002.570956453.0000000000402000.00000040.00000001.sdmp |
String found in binary or memory: https://api.telegram.org/bot%telegramapi%/ |
Source: MSBuild.exe, 00000003.00000002.575561117.0000000003401000.00000004.00000001.sdmp |
String found in binary or memory: https://api.telegram.org/bot%telegramapi%/sendDocumentdocument---------------------------x |
Source: MSBuild.exe, 00000003.00000002.578757614.00000000036D8000.00000004.00000001.sdmp |
String found in binary or memory: https://sectigo.com/CPS0 |
Source: Statement of Account.exe, 00000000.00000002.230197757.0000000003B5F000.00000004.00000001.sdmp, MSBuild.exe, 00000003.00000002.570956453.0000000000402000.00000040.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: MSBuild.exe, 00000003.00000002.575561117.0000000003401000.00000004.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Code function: 0_2_005E9013 |
0_2_005E9013 |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Code function: 0_2_05BCDD78 |
0_2_05BCDD78 |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Code function: 0_2_05BC0D80 |
0_2_05BC0D80 |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Code function: 0_2_05BC2D1A |
0_2_05BC2D1A |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Code function: 0_2_05BC0D73 |
0_2_05BC0D73 |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Code function: 0_2_05BC71D0 |
0_2_05BC71D0 |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Code function: 0_2_05BC0B28 |
0_2_05BC0B28 |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Code function: 0_2_05BC0B18 |
0_2_05BC0B18 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018A2D50 |
3_2_018A2D50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018A1FE0 |
3_2_018A1FE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018A2618 |
3_2_018A2618 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018ABC90 |
3_2_018ABC90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018AB6B2 |
3_2_018AB6B2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B4DE0 |
3_2_018B4DE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B8148 |
3_2_018B8148 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B1CA8 |
3_2_018B1CA8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B0040 |
3_2_018B0040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018BAF10 |
3_2_018BAF10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B62B8 |
3_2_018B62B8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B2228 |
3_2_018B2228 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B5984 |
3_2_018B5984 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B15A0 |
3_2_018B15A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B30E8 |
3_2_018B30E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B0006 |
3_2_018B0006 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 3_2_018B4470 |
3_2_018B4470 |
Source: Statement of Account.exe |
Binary or memory string: OriginalFilename vs Statement of Account.exe |
Source: Statement of Account.exe, 00000000.00000002.230197757.0000000003B5F000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenamePositiveSign.dll< vs Statement of Account.exe |
Source: Statement of Account.exe, 00000000.00000002.230197757.0000000003B5F000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameWknSFDcbckSWaOKzgGLUFEXl.exe4 vs Statement of Account.exe |
Source: Statement of Account.exe, 00000000.00000002.231640208.0000000005080000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamemscorrc.dllT vs Statement of Account.exe |
Source: Statement of Account.exe, 00000000.00000002.232246201.0000000006330000.00000002.00000001.sdmp |
Binary or memory string: originalfilename vs Statement of Account.exe |
Source: Statement of Account.exe, 00000000.00000002.232246201.0000000006330000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamepropsys.dll.mui@ vs Statement of Account.exe |
Source: Statement of Account.exe, 00000000.00000002.232115938.0000000006230000.00000002.00000001.sdmp |
Binary or memory string: System.OriginalFileName vs Statement of Account.exe |
Source: Statement of Account.exe, 00000000.00000002.226939426.00000000005E2000.00000002.00020000.sdmp |
Binary or memory string: OriginalFilenameSessionInfo.exe@ vs Statement of Account.exe |
Source: Statement of Account.exe, 00000000.00000002.227700296.0000000002B01000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameSoapName.dll2 vs Statement of Account.exe |
Source: Statement of Account.exe |
Binary or memory string: OriginalFilenameSessionInfo.exe@ vs Statement of Account.exe |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: Statement of Account.exe, 00000000.00000002.227700296.0000000002B01000.00000004.00000001.sdmp |
Binary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: MSBuild.exe, 00000003.00000002.588194103.0000000006510000.00000002.00000001.sdmp |
Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: Statement of Account.exe, 00000000.00000002.227700296.0000000002B01000.00000004.00000001.sdmp |
Binary or memory string: vmware |
Source: MSBuild.exe, 00000003.00000002.588194103.0000000006510000.00000002.00000001.sdmp |
Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: MSBuild.exe, 00000003.00000002.588194103.0000000006510000.00000002.00000001.sdmp |
Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: Statement of Account.exe, 00000000.00000002.227700296.0000000002B01000.00000004.00000001.sdmp |
Binary or memory string: VMware SVGA II |
Source: MSBuild.exe, 00000003.00000003.424749334.0000000006619000.00000004.00000001.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: Statement of Account.exe, 00000000.00000002.227700296.0000000002B01000.00000004.00000001.sdmp |
Binary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools |
Source: MSBuild.exe, 00000003.00000002.588194103.0000000006510000.00000002.00000001.sdmp |
Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Queries volume information: C:\Users\user\Desktop\Statement of Account.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\Statement of Account.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |