Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.910158370.0000000003091000.00000004.00000001.sdmp | String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.910607840.000000000341B000.00000004.00000001.sdmp | String found in binary or memory: http://1300dentrepair.com.au |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.910158370.0000000003091000.00000004.00000001.sdmp | String found in binary or memory: http://DynDns.comDynDNS |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.910158370.0000000003091000.00000004.00000001.sdmp | String found in binary or memory: http://WArrNU.com |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://fontfabrik.com |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.910607840.000000000341B000.00000004.00000001.sdmp | String found in binary or memory: http://mail.1300dentrepair.com.au |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668911684.00000000030F1000.00000004.00000001.sdmp, NEW-P&I_Circularpdf.exe, 00000000.00000002.668996521.0000000003155000.00000004.00000001.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668996521.0000000003155000.00000004.00000001.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name4 |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645181408.0000000006173000.00000004.00000001.sdmp | String found in binary or memory: http://www.carterandcone.com |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.carterandcone.coml |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers? |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designersG |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.677713745.000000000617A000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.comF |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.677713745.000000000617A000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.come.com |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.677713745.000000000617A000.00000004.00000001.sdmp | String found in binary or memory: http://www.fontbureau.comicFa |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.fonts.com |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.642100886.000000000618B000.00000004.00000001.sdmp | String found in binary or memory: http://www.fonts.comc |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.642120228.000000000618B000.00000004.00000001.sdmp | String found in binary or memory: http://www.fonts.comn |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.founder.com.cn/cn |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.goodfont.co.kr |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645181408.0000000006173000.00000004.00000001.sdmp, NEW-P&I_Circularpdf.exe, 00000000.00000003.645737096.000000000617A000.00000004.00000001.sdmp, NEW-P&I_Circularpdf.exe, 00000000.00000003.645525062.000000000617C000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645558257.0000000006173000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/9 |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645558257.0000000006173000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/F |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645558257.0000000006173000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/H |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645181408.0000000006173000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/T |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645321880.0000000006175000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/Y0dl |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645321880.0000000006175000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/a |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645525062.000000000617C000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/h |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645321880.0000000006175000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/j |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645321880.0000000006175000.00000004.00000001.sdmp, NEW-P&I_Circularpdf.exe, 00000000.00000003.645558257.0000000006173000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/jp/ |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645321880.0000000006175000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/jp/F |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645321880.0000000006175000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/jp/T |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645737096.000000000617A000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/jp/x |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.645321880.0000000006175000.00000004.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/x |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.sajatypeworks.com |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.sakkal.com |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.sandoll.co.kr |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.tiro.com |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.typography.netD |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.urwpp.deDPlease |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678400926.0000000007382000.00000004.00000001.sdmp | String found in binary or memory: http://www.zhongyicts.com.cn |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.910158370.0000000003091000.00000004.00000001.sdmp | String found in binary or memory: https://N2oCWMiTpgUuukNONm.com |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.910158370.0000000003091000.00000004.00000001.sdmp | String found in binary or memory: https://api.ipify.org%$ |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.910158370.0000000003091000.00000004.00000001.sdmp | String found in binary or memory: https://api.ipify.org%GETMozilla/5.0 |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | String found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.670515313.000000000428B000.00000004.00000001.sdmp, NEW-P&I_Circularpdf.exe, 00000008.00000002.907967195.0000000000402000.00000040.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.910158370.0000000003091000.00000004.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_030AC2B0 | 0_2_030AC2B0 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_030A99D8 | 0_2_030A99D8 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07784680 | 0_2_07784680 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07784430 | 0_2_07784430 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07786239 | 0_2_07786239 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07782080 | 0_2_07782080 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07787FA8 | 0_2_07787FA8 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07786E28 | 0_2_07786E28 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07788ED8 | 0_2_07788ED8 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0778B631 | 0_2_0778B631 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0778B478 | 0_2_0778B478 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0778B468 | 0_2_0778B468 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07784420 | 0_2_07784420 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0778B238 | 0_2_0778B238 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0778B237 | 0_2_0778B237 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0778F2D8 | 0_2_0778F2D8 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0778B018 | 0_2_0778B018 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0778B008 | 0_2_0778B008 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07789E00 | 0_2_07789E00 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07788E87 | 0_2_07788E87 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07789DF3 | 0_2_07789DF3 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07786DBB | 0_2_07786DBB |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0778ECA0 | 0_2_0778ECA0 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07787A10 | 0_2_07787A10 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0778A928 | 0_2_0778A928 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07830D6A | 0_2_07830D6A |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_0783B3A0 | 0_2_0783B3A0 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_078363D8 | 0_2_078363D8 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07836AF0 | 0_2_07836AF0 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07837108 | 0_2_07837108 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_078398B9 | 0_2_078398B9 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07832868 | 0_2_07832868 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_07837F60 | 0_2_07837F60 |
Source: NEW-P&I_Circularpdf.exe | Binary or memory string: OriginalFilename vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenamelxgPVjCYHXruETfsTJKCQTgBrkYF.exe4 vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000003.654247974.0000000004259000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameDSASignature.dll" vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.680442001.000000000DD40000.00000002.00000001.sdmp | Binary or memory string: System.OriginalFileName vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678597649.0000000007760000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameSimpleUI.dll2 vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000000.639082381.0000000000D52000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenameIComparable.exe< vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.680709898.000000000DE40000.00000002.00000001.sdmp | Binary or memory string: originalfilename vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.680709898.000000000DE40000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamepropsys.dll.mui@ vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe | Binary or memory string: OriginalFilename vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000007.00000000.665767950.0000000000132000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenameIComparable.exe< vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.907967195.0000000000402000.00000040.00000001.sdmp | Binary or memory string: OriginalFilenamelxgPVjCYHXruETfsTJKCQTgBrkYF.exe4 vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000000.666790676.0000000000A32000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenameIComparable.exe< vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.909000081.0000000001320000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamemscorrc.dllT vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.908201620.0000000000EF8000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameUNKNOWN_FILET vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000002.908505839.0000000001060000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamewshom.ocx.mui vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe | Binary or memory string: OriginalFilenameIComparable.exe< vs NEW-P&I_Circularpdf.exe |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: Select * from UnmanagedMemoryStreamWrapper WHERE modelo=@modelo;? |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: Select * from Clientes WHERE id=@id;; |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: Select * from Aluguel5Erro ao listar Banco sql-UnmanagedMemoryStreamWrapper.INSERT INTO Aluguel VALUES(@clienteID, @data); |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: INSERT INTO UnmanagedMemoryStreamWrapper VALUES(@modelo, @fabricante, @ano, @cor); |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: INSERT INTO Itens_Aluguel VALUES(@aluguelID, @aviaoID, @validade); |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: Insert into Clientes values (@nome, @cpf, @rg, @cidade, @endereco, @uf, @telefone); |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: INSERT INTO Aluguel VALUES(@clienteID, @data); |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 0_2_00D55955 push es; ret | 0_2_00D55965 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 7_2_00135955 push es; ret | 7_2_00135965 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 8_3_012E9246 pushfd ; retf | 8_3_012E9261 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 8_3_012E9246 pushfd ; retf | 8_3_012E9261 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 8_3_012E9246 pushfd ; retf | 8_3_012E9261 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 8_3_012E9246 pushfd ; retf | 8_3_012E9261 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 8_3_012E9246 pushfd ; retf | 8_3_012E9261 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 8_3_012E9246 pushfd ; retf | 8_3_012E9261 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 8_3_012E9246 pushfd ; retf | 8_3_012E9261 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 8_3_012E9246 pushfd ; retf | 8_3_012E9261 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Code function: 8_3_012E9246 pushfd ; retf | 8_3_012E9261 |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\NEW-P&I_Circularpdf.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.678923352.0000000007AF5000.00000004.00000001.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{e6e9dfd8-98f2-11e9-90ce-806e6f6e6963}\DosDevices\D: |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: vmware |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: SOFTWARE\VMware, Inc.\VMware Tools |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: VMware SVGA II!Add-MpPreference -ExclusionPath " |
Source: NEW-P&I_Circularpdf.exe | Binary or memory string: Hyper-V RAW |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: VMWARE |
Source: NEW-P&I_Circularpdf.exe, 00000008.00000003.890791103.00000000012E1000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllG |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: InstallPath%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: VMWARE"SOFTWARE\VMware, Inc.\VMware ToolsLHARDWARE\DEVICEMAP\Scsi\Scsi Port 1\Scsi Bus 0\Target Id 0\Logical Unit Id 0LHARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0\Target Id 0\Logical Unit Id 0'SYSTEM\ControlSet001\Services\Disk\Enum |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: VMware SVGA II |
Source: NEW-P&I_Circularpdf.exe, 00000000.00000002.668971601.000000000313C000.00000004.00000001.sdmp | Binary or memory string: vmwareNSYSTEM\ControlSet001\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000 |