Source: QUOTE 7129.exe, 00000001.00000002.511615461.0000000002E61000.00000004.00000001.sdmp |
String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: QUOTE 7129.exe, 00000001.00000002.511615461.0000000002E61000.00000004.00000001.sdmp |
String found in binary or memory: http://DynDns.comDynDNS |
Source: QUOTE 7129.exe, 00000001.00000002.511615461.0000000002E61000.00000004.00000001.sdmp |
String found in binary or memory: http://RSNcbZ.com |
Source: QUOTE 7129.exe |
String found in binary or memory: http://gcr.github.com/super-sudoku-for-windows/ |
Source: QUOTE 7129.exe, 00000000.00000002.243646942.0000000002B91000.00000004.00000001.sdmp |
String found in binary or memory: http://www.collada.org/2005/11/COLLADASchema9Done |
Source: QUOTE 7129.exe, 00000000.00000002.244101705.0000000003B99000.00000004.00000001.sdmp, QUOTE 7129.exe, 00000001.00000002.506588894.0000000000402000.00000040.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: QUOTE 7129.exe, 00000001.00000002.511615461.0000000002E61000.00000004.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_007A4FE4 |
0_2_007A4FE4 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_00FCC124 |
0_2_00FCC124 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_00FCE570 |
0_2_00FCE570 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_00FCE560 |
0_2_00FCE560 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F80040 |
0_2_05F80040 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F86010 |
0_2_05F86010 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F86000 |
0_2_05F86000 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F80006 |
0_2_05F80006 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F80346 |
0_2_05F80346 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_009E4FE4 |
1_2_009E4FE4 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BCAB70 |
1_2_00BCAB70 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BC2D50 |
1_2_00BC2D50 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BC2618 |
1_2_00BC2618 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BC1FE1 |
1_2_00BC1FE1 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BCCA68 |
1_2_00BCCA68 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BC9DB8 |
1_2_00BC9DB8 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BD4660 |
1_2_00BD4660 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BDA8E8 |
1_2_00BDA8E8 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BD5D80 |
1_2_00BD5D80 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_014246A0 |
1_2_014246A0 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_01424690 |
1_2_01424690 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_0142DA00 |
1_2_0142DA00 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BCD2B8 |
1_2_00BCD2B8 |
Source: QUOTE 7129.exe |
Binary or memory string: OriginalFilename vs QUOTE 7129.exe |
Source: QUOTE 7129.exe, 00000000.00000002.243646942.0000000002B91000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenamejOUkZdFMCThYhhcCysTX.exe4 vs QUOTE 7129.exe |
Source: QUOTE 7129.exe, 00000000.00000002.246572300.0000000005E80000.00000004.00020000.sdmp |
Binary or memory string: OriginalFilenameUI.dll< vs QUOTE 7129.exe |
Source: QUOTE 7129.exe |
Binary or memory string: OriginalFilename vs QUOTE 7129.exe |
Source: QUOTE 7129.exe, 00000001.00000002.506867447.0000000000438000.00000040.00000001.sdmp |
Binary or memory string: OriginalFilenamejOUkZdFMCThYhhcCysTX.exe4 vs QUOTE 7129.exe |
Source: QUOTE 7129.exe, 00000001.00000002.509760538.00000000012AA000.00000004.00000020.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs QUOTE 7129.exe |
Source: QUOTE 7129.exe, 00000001.00000002.508685597.0000000000EF8000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameUNKNOWN_FILET vs QUOTE 7129.exe |
Source: QUOTE 7129.exe |
Binary or memory string: OriginalFilenameContinuationResultTaskFromTa.exe8 vs QUOTE 7129.exe |
Source: QUOTE 7129.exe, WelcomeForm.cs |
.Net Code: ExceptionFromErrorCode System.Reflection.Assembly System.AppDomain::Load(System.Byte[]) |
Source: 0.0.QUOTE 7129.exe.7a0000.0.unpack, WelcomeForm.cs |
.Net Code: ExceptionFromErrorCode System.Reflection.Assembly System.AppDomain::Load(System.Byte[]) |
Source: 0.2.QUOTE 7129.exe.7a0000.0.unpack, WelcomeForm.cs |
.Net Code: ExceptionFromErrorCode System.Reflection.Assembly System.AppDomain::Load(System.Byte[]) |
Source: 1.0.QUOTE 7129.exe.9e0000.0.unpack, WelcomeForm.cs |
.Net Code: ExceptionFromErrorCode System.Reflection.Assembly System.AppDomain::Load(System.Byte[]) |
Source: 1.2.QUOTE 7129.exe.9e0000.1.unpack, WelcomeForm.cs |
.Net Code: ExceptionFromErrorCode System.Reflection.Assembly System.AppDomain::Load(System.Byte[]) |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_007A800D push es; ret |
0_2_007A8018 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_00FCF930 pushad ; iretd |
0_2_00FCF931 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F84513 push ss; ret |
0_2_05F84516 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F84126 push ss; ret |
0_2_05F84127 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F8505D push E9FFFFFEh; retf |
0_2_05F85062 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F83FD2 push FFFFFFF1h; ret |
0_2_05F83FD4 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F84F42 pushfd ; iretd |
0_2_05F84F43 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F83F36 push es; ret |
0_2_05F83F37 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F84ED0 pushad ; iretd |
0_2_05F84ED1 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 0_2_05F85BA0 push 28054CD0h; iretd |
0_2_05F85BAD |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_009E800D push es; ret |
1_2_009E8018 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BC7A37 push edi; retn 0000h |
1_2_00BC7A39 |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BC8326 push ecx; retf |
1_2_00BC832C |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BC8352 push ecx; retf |
1_2_00BC832C |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Code function: 1_2_00BD05C8 push 3C00BBCBh; retf |
1_2_00BD05CD |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: QUOTE 7129.exe, 00000000.00000002.243646942.0000000002B91000.00000004.00000001.sdmp |
Binary or memory string: VMware SVGA IIBAdd-MpPreference -ExclusionPath " |
Source: QUOTE 7129.exe, 00000000.00000002.243646942.0000000002B91000.00000004.00000001.sdmp |
Binary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: QUOTE 7129.exe, 00000000.00000002.243646942.0000000002B91000.00000004.00000001.sdmp |
Binary or memory string: vmware |
Source: QUOTE 7129.exe, 00000000.00000002.243646942.0000000002B91000.00000004.00000001.sdmp |
Binary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools |
Source: QUOTE 7129.exe, 00000001.00000002.510914977.00000000017E0000.00000002.00020000.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: QUOTE 7129.exe, 00000001.00000002.510914977.00000000017E0000.00000002.00020000.sdmp |
Binary or memory string: Progman |
Source: QUOTE 7129.exe, 00000001.00000002.510914977.00000000017E0000.00000002.00020000.sdmp |
Binary or memory string: SProgram Managerl |
Source: QUOTE 7129.exe, 00000001.00000002.510914977.00000000017E0000.00000002.00020000.sdmp |
Binary or memory string: Shell_TrayWnd, |
Source: QUOTE 7129.exe, 00000001.00000002.510914977.00000000017E0000.00000002.00020000.sdmp |
Binary or memory string: Progmanlock |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Users\user\Desktop\QUOTE 7129.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Users\user\Desktop\QUOTE 7129.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTE 7129.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: Yara match |
File source: 0.2.QUOTE 7129.exe.3c15220.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTE 7129.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.QUOTE 7129.exe.3c15220.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000000.00000002.244101705.0000000003B99000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.506588894.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.244299750.0000000003C99000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.511981128.0000000002F0E000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.511615461.0000000002E61000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: QUOTE 7129.exe PID: 6056, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: QUOTE 7129.exe PID: 5876, type: MEMORYSTR |
Source: Yara match |
File source: 0.2.QUOTE 7129.exe.3c15220.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTE 7129.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.QUOTE 7129.exe.3c15220.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000000.00000002.244101705.0000000003B99000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.506588894.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.244299750.0000000003C99000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.511981128.0000000002F0E000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.511615461.0000000002E61000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: QUOTE 7129.exe PID: 6056, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: QUOTE 7129.exe PID: 5876, type: MEMORYSTR |