Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014005284C |
1_2_000000014005284C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140048A4C |
1_2_0000000140048A4C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140040370 |
1_2_0000000140040370 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400343E8 |
1_2_00000001400343E8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140026C74 |
1_2_0000000140026C74 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004F4D0 |
1_2_000000014004F4D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140049CE8 |
1_2_0000000140049CE8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004357C |
1_2_000000014004357C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014003DEEC |
1_2_000000014003DEEC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140036778 |
1_2_0000000140036778 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140022004 |
1_2_0000000140022004 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140060014 |
1_2_0000000140060014 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140024028 |
1_2_0000000140024028 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002782C |
1_2_000000014002782C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002E030 |
1_2_000000014002E030 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014005582B |
1_2_000000014005582B |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140034044 |
1_2_0000000140034044 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014000F848 |
1_2_000000014000F848 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014003D878 |
1_2_000000014003D878 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140020094 |
1_2_0000000140020094 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002F8A4 |
1_2_000000014002F8A4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400280AC |
1_2_00000001400280AC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004F0AC |
1_2_000000014004F0AC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400410B4 |
1_2_00000001400410B4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400150E4 |
1_2_00000001400150E4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140066100 |
1_2_0000000140066100 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140025100 |
1_2_0000000140025100 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004D914 |
1_2_000000014004D914 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140033124 |
1_2_0000000140033124 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140032128 |
1_2_0000000140032128 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140025930 |
1_2_0000000140025930 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140005950 |
1_2_0000000140005950 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004E954 |
1_2_000000014004E954 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140001158 |
1_2_0000000140001158 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014003796C |
1_2_000000014003796C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140049980 |
1_2_0000000140049980 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140039990 |
1_2_0000000140039990 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002F198 |
1_2_000000014002F198 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400389A4 |
1_2_00000001400389A4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400099AC |
1_2_00000001400099AC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400659F0 |
1_2_00000001400659F0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002EA1C |
1_2_000000014002EA1C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140055A4D |
1_2_0000000140055A4D |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014005A24C |
1_2_000000014005A24C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014001B250 |
1_2_000000014001B250 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140001A78 |
1_2_0000000140001A78 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140007284 |
1_2_0000000140007284 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140061283 |
1_2_0000000140061283 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140061A90 |
1_2_0000000140061A90 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400642A0 |
1_2_00000001400642A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002DAA4 |
1_2_000000014002DAA4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140043AC0 |
1_2_0000000140043AC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140019AC4 |
1_2_0000000140019AC4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400512E0 |
1_2_00000001400512E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400162E0 |
1_2_00000001400162E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002BAEC |
1_2_000000014002BAEC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140006AEC |
1_2_0000000140006AEC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140063324 |
1_2_0000000140063324 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140013B64 |
1_2_0000000140013B64 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140055364 |
1_2_0000000140055364 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140019378 |
1_2_0000000140019378 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140060B8C |
1_2_0000000140060B8C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014001A394 |
1_2_000000014001A394 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140008B94 |
1_2_0000000140008B94 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004BBBC |
1_2_000000014004BBBC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140021BD8 |
1_2_0000000140021BD8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400243E0 |
1_2_00000001400243E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002B3F3 |
1_2_000000014002B3F3 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140004C0C |
1_2_0000000140004C0C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002B429 |
1_2_000000014002B429 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140012474 |
1_2_0000000140012474 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014000AC74 |
1_2_000000014000AC74 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140038478 |
1_2_0000000140038478 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004FC74 |
1_2_000000014004FC74 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002747C |
1_2_000000014002747C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002A4A4 |
1_2_000000014002A4A4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014001B4AC |
1_2_000000014001B4AC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004A4B0 |
1_2_000000014004A4B0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140063CB4 |
1_2_0000000140063CB4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002F4B8 |
1_2_000000014002F4B8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140003CC4 |
1_2_0000000140003CC4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014000ECD0 |
1_2_000000014000ECD0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140017CD4 |
1_2_0000000140017CD4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140044CD8 |
1_2_0000000140044CD8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004ECF8 |
1_2_000000014004ECF8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140042504 |
1_2_0000000140042504 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140026534 |
1_2_0000000140026534 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002AD38 |
1_2_000000014002AD38 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140022D50 |
1_2_0000000140022D50 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140029550 |
1_2_0000000140029550 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140012D8C |
1_2_0000000140012D8C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140051D90 |
1_2_0000000140051D90 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140006D94 |
1_2_0000000140006D94 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400515A0 |
1_2_00000001400515A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400285AC |
1_2_00000001400285AC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140031DCC |
1_2_0000000140031DCC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400365D0 |
1_2_00000001400365D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400205D8 |
1_2_00000001400205D8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140011DE4 |
1_2_0000000140011DE4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004D5EC |
1_2_000000014004D5EC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014003A60C |
1_2_000000014003A60C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140021E1C |
1_2_0000000140021E1C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140023E1C |
1_2_0000000140023E1C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004E628 |
1_2_000000014004E628 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004CE2C |
1_2_000000014004CE2C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140018638 |
1_2_0000000140018638 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140004E38 |
1_2_0000000140004E38 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140014644 |
1_2_0000000140014644 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002EE48 |
1_2_000000014002EE48 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004A660 |
1_2_000000014004A660 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140053670 |
1_2_0000000140053670 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014003AE70 |
1_2_000000014003AE70 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140031670 |
1_2_0000000140031670 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014002D694 |
1_2_000000014002D694 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140036E98 |
1_2_0000000140036E98 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014000D69C |
1_2_000000014000D69C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140050EA8 |
1_2_0000000140050EA8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140053EC0 |
1_2_0000000140053EC0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014001BEC8 |
1_2_000000014001BEC8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400466C4 |
1_2_00000001400466C4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014004EF0C |
1_2_000000014004EF0C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140017F40 |
1_2_0000000140017F40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014001CF40 |
1_2_000000014001CF40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140041F3C |
1_2_0000000140041F3C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140032750 |
1_2_0000000140032750 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014000578C |
1_2_000000014000578C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400137A0 |
1_2_00000001400137A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400557A3 |
1_2_00000001400557A3 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014001C7CC |
1_2_000000014001C7CC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_00000001400027DC |
1_2_00000001400027DC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_0000000140030FE0 |
1_2_0000000140030FE0 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E438E368 |
24_2_00007FF7E438E368 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E4382F54 |
24_2_00007FF7E4382F54 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E438CFF0 |
24_2_00007FF7E438CFF0 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E4390A58 |
24_2_00007FF7E4390A58 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E4392438 |
24_2_00007FF7E4392438 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E4386848 |
24_2_00007FF7E4386848 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E4387EFC |
24_2_00007FF7E4387EFC |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E438E368 |
28_2_00007FF7E438E368 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E4382F54 |
28_2_00007FF7E4382F54 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E438CFF0 |
28_2_00007FF7E438CFF0 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E4390A58 |
28_2_00007FF7E4390A58 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E4392438 |
28_2_00007FF7E4392438 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E4386848 |
28_2_00007FF7E4386848 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E4387EFC |
28_2_00007FF7E4387EFC |
Source: C:\Windows\System32\CCAL\MDMAppInstaller.exe |
Code function: 31_2_00007FF6C5244648 |
31_2_00007FF6C5244648 |
Source: C:\Windows\System32\CCAL\MDMAppInstaller.exe |
Code function: 31_2_00007FF6C52519D4 |
31_2_00007FF6C52519D4 |
Source: C:\Windows\System32\CCAL\MDMAppInstaller.exe |
Code function: 31_2_00007FF6C5249630 |
31_2_00007FF6C5249630 |
Source: C:\Windows\System32\CCAL\MDMAppInstaller.exe |
Code function: 31_2_00007FF6C52549FF |
31_2_00007FF6C52549FF |
Source: C:\Windows\System32\CCAL\MDMAppInstaller.exe |
Code function: 31_2_00007FF6C524E934 |
31_2_00007FF6C524E934 |
Source: C:\Windows\System32\CCAL\MDMAppInstaller.exe |
Code function: 31_2_00007FF6C5243FAC |
31_2_00007FF6C5243FAC |
Source: C:\Windows\System32\CCAL\MDMAppInstaller.exe |
Code function: 31_2_00007FF6C5246BDC |
31_2_00007FF6C5246BDC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 1_2_000000014005284C NtQuerySystemInformation, |
1_2_000000014005284C |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E438E368 ZwQueryWnfStateNameInformation,ZwUpdateWnfStateData,EtwEventWriteNoRegistration,NtQuerySystemInformation,NtOpenEvent,NtWaitForSingleObject,NtClose,RtlAllocateAndInitializeSid,RtlInitUnicodeString,memset,NtAlpcConnectPort,memset,NtAlpcSendWaitReceivePort,RtlFreeSid,NtClose, |
24_2_00007FF7E438E368 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E4391F54 NtQueryLicenseValue, |
24_2_00007FF7E4391F54 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E4388404 DbgPrintEx,NtQueryInformationProcess,DbgPrintEx,DbgPrintEx,ReadProcessMemory,DbgPrintEx,GetLastError, |
24_2_00007FF7E4388404 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E4392438 LoadLibraryExW,GetProcAddress,NtQueryLicenseValue,FreeLibrary,NtQueryLicenseValue, |
24_2_00007FF7E4392438 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 24_2_00007FF7E43882EC DbgPrintEx,NtQueryInformationProcess,DbgPrintEx,DbgPrintEx,ReadProcessMemory,DbgPrintEx,GetLastError, |
24_2_00007FF7E43882EC |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E438E368 ZwQueryWnfStateNameInformation,ZwUpdateWnfStateData,EtwEventWriteNoRegistration,NtQuerySystemInformation,NtOpenEvent,NtWaitForSingleObject,NtClose,RtlAllocateAndInitializeSid,RtlInitUnicodeString,memset,NtAlpcConnectPort,memset,NtAlpcSendWaitReceivePort,RtlFreeSid,NtClose, |
28_2_00007FF7E438E368 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E4391F54 NtQueryLicenseValue, |
28_2_00007FF7E4391F54 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E4388404 DbgPrintEx,NtQueryInformationProcess,DbgPrintEx,DbgPrintEx,ReadProcessMemory,DbgPrintEx,GetLastError, |
28_2_00007FF7E4388404 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E4392438 LoadLibraryExW,GetProcAddress,NtQueryLicenseValue,FreeLibrary,NtQueryLicenseValue, |
28_2_00007FF7E4392438 |
Source: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe |
Code function: 28_2_00007FF7E43882EC DbgPrintEx,NtQueryInformationProcess,DbgPrintEx,DbgPrintEx,ReadProcessMemory,DbgPrintEx,GetLastError, |
28_2_00007FF7E43882EC |
Source: unknown |
Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\x64.dll" |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\x64.dll",#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\x64.dll,IsInteractiveUserSession |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\x64.dll",#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\x64.dll,QueryActiveSession |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\x64.dll,QueryUserToken |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\wermgr.exe C:\Windows\system32\wermgr.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user\AppData\Local\Temp\Cjaq.cmd |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe "C:\Users\user\AppData\Roaming\R3POs\wermgr.exe" |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\MDMAppInstaller.exe C:\Windows\system32\MDMAppInstaller.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user\AppData\Local\Temp\tkcfGo.cmd |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe "C:\Users\user\AppData\Roaming\R3POs\wermgr.exe" |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /F /TN "Jvadjthzpd" /TR C:\Windows\system32\CCAL\MDMAppInstaller.exe /SC minute /MO 60 /RL highest |
|
Source: C:\Windows\System32\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: unknown |
Process created: C:\Windows\System32\CCAL\MDMAppInstaller.exe C:\Windows\system32\CCAL\MDMAppInstaller.exe |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe "C:\Users\user\AppData\Roaming\R3POs\wermgr.exe" |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
|
Source: C:\Windows\System32\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
|
Source: C:\Windows\System32\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
|
Source: C:\Windows\System32\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
|
Source: C:\Windows\System32\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
|
Source: C:\Windows\System32\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
|
Source: C:\Windows\System32\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
|
Source: C:\Windows\System32\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\x64.dll",#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\x64.dll,IsInteractiveUserSession |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\x64.dll,QueryActiveSession |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\x64.dll,QueryUserToken |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\x64.dll",#1 |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\wermgr.exe C:\Windows\system32\wermgr.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user\AppData\Local\Temp\Cjaq.cmd |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe "C:\Users\user\AppData\Roaming\R3POs\wermgr.exe" |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\MDMAppInstaller.exe C:\Windows\system32\MDMAppInstaller.exe |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user\AppData\Local\Temp\tkcfGo.cmd |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe "C:\Users\user\AppData\Roaming\R3POs\wermgr.exe" |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /F /TN "Jvadjthzpd" /TR C:\Windows\system32\CCAL\MDMAppInstaller.exe /SC minute /MO 60 /RL highest |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Users\user\AppData\Roaming\R3POs\wermgr.exe "C:\Users\user\AppData\Roaming\R3POs\wermgr.exe" |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
Jump to behavior |
Source: C:\Windows\explorer.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks.exe /Query /TN "Jvadjthzpd" |
Jump to behavior |
Source: x64.dll |
Static PE information: section name: .crt1 |
Source: x64.dll |
Static PE information: section name: qwTG |
Source: x64.dll |
Static PE information: section name: .lqen |
Source: x64.dll |
Static PE information: section name: .vqb |
Source: x64.dll |
Static PE information: section name: .gjd |
Source: x64.dll |
Static PE information: section name: .wqhqlp |
Source: x64.dll |
Static PE information: section name: .jriz |
Source: x64.dll |
Static PE information: section name: .ebkl |
Source: x64.dll |
Static PE information: section name: .aoj |
Source: x64.dll |
Static PE information: section name: .ncm |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: .crt1 |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: qwTG |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: .lqen |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: .vqb |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: .gjd |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: .wqhqlp |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: .jriz |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: .ebkl |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: .aoj |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: .ncm |
Source: KHNE9A4.tmp.5.dr |
Static PE information: section name: .gqytqb |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: .crt1 |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: qwTG |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: .lqen |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: .vqb |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: .gjd |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: .wqhqlp |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: .jriz |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: .ebkl |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: .aoj |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: .ncm |
Source: NAmADA4.tmp.5.dr |
Static PE information: section name: .ksjw |
Source: wermgr.exe.17.dr |
Static PE information: section name: .imrsiv |
Source: wermgr.exe.17.dr |
Static PE information: section name: .didat |
Source: MDMAppInstaller.exe.26.dr |
Static PE information: section name: .didat |
Source: explorer.exe, 00000005.00000000.425051454.0000000007EF6000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\5&1ec51bf7&0&000000 |
Source: explorer.exe, 00000005.00000000.441628996.000000000807B000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}8Ll/ |
Source: explorer.exe, 00000005.00000000.441628996.000000000807B000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000005.00000000.425184192.0000000007F91000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: VMware SATA CD00 |
Source: explorer.exe, 00000005.00000000.426024313.00000000081C7000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: 0d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATAY |
Source: explorer.exe, 00000005.00000000.472787622.0000000006915000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000005.00000000.443698787.00000000081C6000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: 0d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATAs |
Source: explorer.exe, 00000005.00000000.441628996.000000000807B000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\5&280B647&0&000000 |
Source: explorer.exe, 00000005.00000000.425184192.0000000007F91000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&000000 |
Source: explorer.exe, 00000005.00000000.425184192.0000000007F91000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: _VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Vir |
Source: explorer.exe, 00000005.00000000.461519524.00000000081C6000.00000004.00000001.00020000.00000000.sdmp |
Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATAs |