Source: ntvdm.exe | String found in binary or memory: http://ipxe.org |
Source: ntvdm.exe | String found in binary or memory: http://ipxe.org) |
Source: ntvdm.exe | String found in binary or memory: http://ipxe.orgiPXE |
Source: C:\Windows\System32\ntvdm.exe | File opened: u: |
Source: C:\Windows\System32\ntvdm.exe | File opened: m: |
Source: C:\Windows\System32\ntvdm.exe | File opened: p: |
Source: C:\Windows\System32\ntvdm.exe | File opened: v: |
Source: C:\Windows\System32\ntvdm.exe | File opened: j: |
Source: C:\Windows\System32\ntvdm.exe | File opened: f: |
Source: C:\Windows\System32\ntvdm.exe | File opened: s: |
Source: C:\Windows\System32\ntvdm.exe | File opened: e: |
Source: C:\Windows\System32\ntvdm.exe | File opened: b: |
Source: C:\Windows\System32\ntvdm.exe | File opened: w: |
Source: C:\Windows\System32\ntvdm.exe | File opened: o: |
Source: C:\Windows\System32\ntvdm.exe | File opened: y: |
Source: C:\Windows\System32\ntvdm.exe | File opened: t: |
Source: C:\Windows\System32\ntvdm.exe | File opened: n: |
Source: C:\Windows\System32\ntvdm.exe | File opened: a: |
Source: C:\Windows\System32\ntvdm.exe | File opened: r: |
Source: C:\Windows\System32\ntvdm.exe | File opened: l: |
Source: C:\Windows\System32\ntvdm.exe | File opened: z: |
Source: C:\Windows\System32\ntvdm.exe | File opened: h: |
Source: C:\Windows\System32\ntvdm.exe | File opened: x: |
Source: C:\Windows\System32\ntvdm.exe | File opened: c: |
Source: C:\Windows\System32\ntvdm.exe | File opened: i: |
Source: C:\Windows\System32\ntvdm.exe | File opened: q: |
Source: C:\Windows\System32\ntvdm.exe | File opened: k: |
Source: C:\Windows\System32\ntvdm.exe | File opened: g: |
Source: C:\Windows\System32\ntvdm.exe | File opened: d: |
Source: classification engine | Classification label: sus22.evad.winEXE@1/1@0/0 |
Source: C:\Windows\System32\ntvdm.exe | File created: C:\Users\HERBBL~1\AppData\Local\Temp\scsD1F3.tmp |
Source: C:\Windows\System32\ntvdm.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Source: ocsp_server.exe | Metascan Online: hash found |
Source: C:\Windows\System32\ntvdm.exe | File created: C:\MSDOS.SYS |
Source: C:\Windows\System32\ntvdm.exe | Section loaded: sfc.dll |
Source: C:\Windows\System32\ntvdm.exe | Section loaded: sfc_os.dll |
Source: C:\Windows\System32\ntvdm.exe | Section loaded: winmm.dll |
Source: C:\Windows\System32\ntvdm.exe | Section loaded: ntvdmd.dll |
Source: C:\Windows\System32\ntvdm.exe | Section loaded: vdmredir.dll |
Source: C:\Windows\System32\ntvdm.exe | Section loaded: netapi32.dll |
Source: C:\Windows\System32\ntvdm.exe | Section loaded: netutils.dll |
Source: C:\Windows\System32\ntvdm.exe | Section loaded: srvcli.dll |
Source: C:\Windows\System32\ntvdm.exe | Section loaded: wkscli.dll |
Source: C:\Windows\System32\ntvdm.exe | Thread register set: target process: unknown |
Source: C:\Windows\System32\ntvdm.exe | Process queried: DebugPort |
Source: C:\Windows\System32\ntvdm.exe | Process queried: DebugPort |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\ntvdm.exe | Process information set: NOOPENFILEERRORBOX |