Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.470294179.00000000032C1000.00000004.00000001.sdmp |
String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.470294179.00000000032C1000.00000004.00000001.sdmp |
String found in binary or memory: http://DynDns.comDynDNS |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.470294179.00000000032C1000.00000004.00000001.sdmp |
String found in binary or memory: http://d58Epg6G54Y2z.org |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.472593846.0000000003574000.00000004.00000001.sdmp |
String found in binary or memory: http://estagold.com.my |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.472593846.0000000003574000.00000004.00000001.sdmp |
String found in binary or memory: http://mail.estagold.com.my |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207036719.0000000002AF1000.00000004.00000001.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.470294179.00000000032C1000.00000004.00000001.sdmp |
String found in binary or memory: http://vHuoap.com |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207036719.0000000002AF1000.00000004.00000001.sdmp |
String found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.208485443.0000000003D57000.00000004.00000001.sdmp, NDKr3inJa9dXEu3.exe, 00000004.00000002.465125878.0000000000402000.00000040.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.470294179.00000000032C1000.00000004.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 1_2_00F2C888 |
1_2_00F2C888 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 1_2_00F2AED4 |
1_2_00F2AED4 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_0143C968 |
4_2_0143C968 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_01432520 |
4_2_01432520 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_01430040 |
4_2_01430040 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_014366B1 |
4_2_014366B1 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_0143C570 |
4_2_0143C570 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_0143D8B0 |
4_2_0143D8B0 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_016E1908 |
4_2_016E1908 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_016E299C |
4_2_016E299C |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_016E0040 |
4_2_016E0040 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_016EB7E8 |
4_2_016EB7E8 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_016E5E10 |
4_2_016E5E10 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_016E0022 |
4_2_016E0022 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_016EAF98 |
4_2_016EAF98 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_016EF230 |
4_2_016EF230 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_032747A0 |
4_2_032747A0 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_03273CCC |
4_2_03273CCC |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_03274730 |
4_2_03274730 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_03274750 |
4_2_03274750 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_032746B0 |
4_2_032746B0 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_032746F0 |
4_2_032746F0 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_03275490 |
4_2_03275490 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_0327D820 |
4_2_0327D820 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_06696C68 |
4_2_06696C68 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_066994F8 |
4_2_066994F8 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_06697538 |
4_2_06697538 |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Code function: 4_2_06696920 |
4_2_06696920 |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.211264396.0000000005D10000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameLegacyPathHandling.dllN vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.211484699.0000000006458000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameDSASignatureDescription.exe< vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.208485443.0000000003D57000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenamemVwpcvWDCJFhCKROeeZLxPCBImYvnKQqhjmag.exe4 vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.211550303.00000000067D0000.00000002.00000001.sdmp |
Binary or memory string: System.OriginalFileName vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207036719.0000000002AF1000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameAsyncState.dllF vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.211746810.00000000068C0000.00000002.00000001.sdmp |
Binary or memory string: originalfilename vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.211746810.00000000068C0000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamepropsys.dll.mui@ vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.466417006.0000000000FE4000.00000002.00020000.sdmp |
Binary or memory string: OriginalFilenameDSASignatureDescription.exe< vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.466551814.0000000001198000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameUNKNOWN_FILET vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.465125878.0000000000402000.00000040.00000001.sdmp |
Binary or memory string: OriginalFilenamemVwpcvWDCJFhCKROeeZLxPCBImYvnKQqhjmag.exe4 vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.468991903.00000000016F0000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamemscorrc.dllT vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.469220197.00000000017B0000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamewshom.ocx.mui vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.469131698.00000000017A0000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamewshom.ocx vs NDKr3inJa9dXEu3.exe |
Source: NDKr3inJa9dXEu3.exe |
Binary or memory string: OriginalFilenameDSASignatureDescription.exe< vs NDKr3inJa9dXEu3.exe |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207036719.0000000002AF1000.00000004.00000001.sdmp |
Binary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207036719.0000000002AF1000.00000004.00000001.sdmp |
Binary or memory string: vmware |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207090813.0000000002B34000.00000004.00000001.sdmp |
Binary or memory string: l%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207090813.0000000002B34000.00000004.00000001.sdmp |
Binary or memory string: VMWARE |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207036719.0000000002AF1000.00000004.00000001.sdmp |
Binary or memory string: VMware SVGA II |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207090813.0000000002B34000.00000004.00000001.sdmp |
Binary or memory string: l"SOFTWARE\VMware, Inc.\VMware T< |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207090813.0000000002B34000.00000004.00000001.sdmp |
Binary or memory string: l"SOFTWARE\VMware, Inc.\VMware T |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207090813.0000000002B34000.00000004.00000001.sdmp |
Binary or memory string: l"SOFTWARE\VMware, Inc.\VMware Tools |
Source: NDKr3inJa9dXEu3.exe, 00000004.00000002.468709042.0000000001668000.00000004.00000020.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: NDKr3inJa9dXEu3.exe, 00000001.00000002.207036719.0000000002AF1000.00000004.00000001.sdmp |
Binary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\NDKr3inJa9dXEu3.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |