Windows Analysis Report
Wefaceswap.exe

Overview

General Information

Sample name: Wefaceswap.exe
Analysis ID: 1447359
MD5: ccacce8535f682dd67c701d9157ef218
SHA1: 5f72f5e427590a0c5e184cb013d27cc3d1af265f
SHA256: f954f818007b508badc400417584ae7726a71f4b697d8b1eb13184318ef1eda1
Infos:

Detection

Score: 16
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

AI detected suspicious sample
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: Submited Sample Integrated Neural Analysis Model: Matched 73.0% probability
Source: Wefaceswap.exe Static PE information: certificate valid
Source: Wefaceswap.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\Users\runneradmin\AppData\Local\Temp\pkg.24e0b2b2d51e47b9dba34c30\node\out\Release\node.pdb\ source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F86CB000.00000002.00000001.01000000.00000003.sdmp
Source: Binary string: C:\Users\runneradmin\AppData\Local\Temp\pkg.24e0b2b2d51e47b9dba34c30\node\out\Release\node.pdb source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F86CB000.00000002.00000001.01000000.00000003.sdmp
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: intergenglobal.com
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://.css
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://.jpg
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://code.google.com/p/closure-compiler/wiki/SourceMaps
Source: Wefaceswap.exe, 00000000.00000003.1264636624.000002A0FE775000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268696034.000002A0FE776000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263416712.000002A0FF089000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263567180.000002A0FF0CB000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263255097.000002A0FF038000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1266167554.000002A0FE776000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263792363.000002A0FF0D5000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265680611.000002A0FF102000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1262889886.000002A0FF031000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.certigna.fr/certignarootca.crl01
Source: Wefaceswap.exe, 00000000.00000002.1269127887.000002A0FE7CF000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264674475.000002A0FE7BE000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263959448.000002A0FE7B3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265365437.000002A0FE7CB000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1266908227.000002A0FE75B000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1266112473.000002A0FE7CF000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265921102.000002A0FE751000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268544966.000002A0FE75C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: Wefaceswap.exe, 00000000.00000003.1264674475.000002A0FE7BE000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272206364.000002A0FF436000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263959448.000002A0FE7B3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268975746.000002A0FE7C9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl
Source: Wefaceswap.exe, 00000000.00000003.1264636624.000002A0FE775000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268696034.000002A0FE776000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263416712.000002A0FF089000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263567180.000002A0FF0CB000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263255097.000002A0FF038000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1266167554.000002A0FE776000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263792363.000002A0FF0D5000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265680611.000002A0FF102000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1262889886.000002A0FF031000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl
Source: Wefaceswap.exe, 00000000.00000003.1264636624.000002A0FE775000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268696034.000002A0FE776000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1266167554.000002A0FE776000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.dhimyotis.com/certignarootca.crlC
Source: Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF4BC000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF4E2000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF4E3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF4E1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl
Source: Wefaceswap.exe, 00000000.00000002.1272206364.000002A0FF436000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: Wefaceswap.exe, 00000000.00000003.1266207183.000002A0FE760000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268653208.000002A0FE768000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1266855821.000002A0FE767000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265921102.000002A0FE751000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.netsolssl.com/NetworkSolutionsCertificateAuthority.crl
Source: Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF4BC000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF4E2000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF4E3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF4E1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/SGCA.crl
Source: Wefaceswap.exe, 00000000.00000003.1264674475.000002A0FE7BE000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263959448.000002A0FE7B3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268975746.000002A0FE7C9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/SGCA.crl0
Source: Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF4BC000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF4E2000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF4E3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF4E1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/STCA.crl
Source: Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/STCA.crl0
Source: Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF4BC000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF4E2000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF4E3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF4E1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl
Source: Wefaceswap.exe, 00000000.00000002.1268744349.000002A0FE787000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264483418.000002A0FE781000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://html4/loose.dtd
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://narwhaljs.org)
Source: Wefaceswap.exe, 00000000.00000003.1266908227.000002A0FE75B000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265921102.000002A0FE751000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268544966.000002A0FE75C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.accv.es
Source: Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF551000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.accv.es0
Source: Wefaceswap.exe, 00000000.00000003.1266908227.000002A0FE75B000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265921102.000002A0FE751000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268544966.000002A0FE75C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.accv.esb.c
Source: Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272206364.000002A0FF436000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://repository.swisssign.com/
Source: Wefaceswap.exe, 00000000.00000002.1272206364.000002A0FF436000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://repository.swisssign.com/PDK
Source: Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://repository.swisssign.com/ZPX
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://src.chromium.org/viewvc/blink/trunk/Source/devtools/front_end/SourceMap.js
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://userguide.icu-project.org/strings/properties
Source: Wefaceswap.exe, 00000000.00000003.1266908227.000002A0FE75B000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265921102.000002A0FE751000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF551000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268544966.000002A0FE75C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0
Source: Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF551000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl
Source: Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF551000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl0
Source: Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF551000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es/legislacion_c.htm
Source: Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF551000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es/legislacion_c.htm0U
Source: Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF551000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es00
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.cert.fnmt.es/dpcs/
Source: Wefaceswap.exe, 00000000.00000003.1263959448.000002A0FE7B3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265905934.000002A0FE7F9000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1269599183.000002A0FE7FA000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264362589.000002A0FE7D3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264658808.000002A0FE7EE000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264596754.000002A0FE7D4000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.cert.fnmt.es/dpcs/tXP4A9xZW$
Source: Wefaceswap.exe, 00000000.00000003.1264506037.000002A0FF10C000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264925299.000002A0FF10D000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1270869396.000002A0FF170000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265712986.000002A0FF120000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263416712.000002A0FF089000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263567180.000002A0FF0CB000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264284255.000002A0FF10B000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263255097.000002A0FF038000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263792363.000002A0FF0D5000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1262889886.000002A0FF031000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1266814813.000002A0FF16E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.firmaprofesional.com/cps0
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://www.midnight-commander.org/browser/lib/tty/key.c
Source: Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF4BC000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF4E2000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF4E3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF4E1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.quovadisglobal.com/cps
Source: Wefaceswap.exe, 00000000.00000003.1264409724.000002A0FE79D000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268833598.000002A0FE7AA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.quovadisglobal.com/cps0
Source: Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF4BC000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF4E2000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF4E3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF4E1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.quovadisglobal.com/cpsO
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://www.squid-cache.org/Doc/config/half_closed_clients/
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://www.unicode.org/copyright.html
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://bugs.chromium.org/p/v8/issues/detail?id=10201
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=745678
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267880959.000001C3DBE41000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://code.google.com/p/chromium/issues/detail?id=25916
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://console.spec.whatwg.org/#clear
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://console.spec.whatwg.org/#console-namespace
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://console.spec.whatwg.org/#count
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://console.spec.whatwg.org/#count-map
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://console.spec.whatwg.org/#countreset
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://console.spec.whatwg.org/#table
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/v8/7848
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://crbug.com/v8/8520
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://cs.chromium.org/chromium/src/v8/tools/SourceMap.js?rcl=dd10454c1d
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/docs/SpiderMonkey/Parser_API
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/docs/Web/API/PerformanceResourceTiming
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Equality_comparisons_and_sameness#Loose_equa
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://encoding.spec.whatwg.org
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://encoding.spec.whatwg.org/#textdecoder
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://encoding.spec.whatwg.org/#textencoder
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://esdiscuss.org/topic/isconstructor#content-11
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://fetch.spec.whatwg.org/
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://fetch.spec.whatwg.org/#fetch-timing-info
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://gist.github.com/XVilka/8346728#gistcomment-2823421
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/WICG/scheduling-apis
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/WebAssembly/esm-integration/issues/42
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/acornjs/acorn/blob/master/acorn/src/identifier.js#L23
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/acornjs/acorn/issues/575
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/addaleax/eventemitter-asyncresource
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/chalk/ansi-regex/blob/HEAD/index.js
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/chalk/supports-color
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/chromium/chromium/blob/HEAD/third_party/blink/public/platform/web_crypto_algorith
Source: Wefaceswap.exe, 00000000.00000002.1267402641.000000E077881000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1267330954.000000D957F81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/cthackers)
Source: Wefaceswap.exe, 00000000.00000002.1267402641.000000E077881000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1267330954.000000D957F81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/cthackers/adm-zip
Source: Wefaceswap.exe, 00000000.00000002.1277679488.000003C983081000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1267402641.000000E077881000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1267330954.000000D957F81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/cthackers/adm-zip.git
Source: Wefaceswap.exe, 00000000.00000002.1267402641.000000E077881000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/cthackers/adm-zip.gity
Source: Wefaceswap.exe, 00000000.00000002.1267402641.000000E077881000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1267330954.000000D957F81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/cthackers/adm-zip/issues
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/da-x/rxvt-unicode/tree/v9.22-with-24bit-color
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/estree/estree/blob/a27003adf4fd7bfad44de9cef372a2eacd527b1c/es5.md#regexpliteral
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/google/caja/blob/HEAD/src/com/google/caja/ses/repairES5.js
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/google/caja/blob/HEAD/src/com/google/caja/ses/startSES.js
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/google/closure-compiler/wiki/Source-Maps
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268042043.0000021383237000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/heycam/webidl/pull/946.
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/isaacs/color-support.
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/joyent/node/issues/3295.
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/libuv/libuv/pull/1501.
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/mafintosh/end-of-stream
Source: Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/mafintosh/pump
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/mysticatea/abort-controller
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node-v0.x-archive/issues/2876.
Source: Wefaceswap.exe, 00000000.00000002.1267017403.000000104EC81000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1241118494.000002A0FF10B000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268192129.0000021A25800000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/blob/1a96d83a223ff9f05f7d942fb84440d323f7b596/lib/internal/bootstrap/
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/commit/ec2822adaad76b126b5cccdeaa1addf2376c9aa6
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/commit/f7620fb96d339f704932f9bb9a0dceb9952df2d4
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/issues
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/10673
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/13435
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1268286112.0000027502FC1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/19009
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/2006
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/2119
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/3392
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/34532
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/35452
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/35475
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/35862
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/35981
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/39707
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1268286112.0000027502FC1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/39758
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/12342
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/12607
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/13870#discussion_r124515293
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/1771#issuecomment-119351671
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/21313
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/26334.
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/30380#issuecomment-552948364
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/30958
Source: Wefaceswap.exe, 00000000.00000002.1267017403.000000104EC81000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1241118494.000002A0FF10B000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268192129.0000021A25800000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/33229
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/33515.
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/33661
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/3394
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1268286112.0000027502FC1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/34010
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267880959.000001C3DBE41000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/34103#issuecomment-652002364
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/34375
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/34385
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/35949#issuecomment-722496598
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267880959.000001C3DBE41000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/36061#discussion_r533718029
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268042043.0000021383237000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/38248
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/38433#issuecomment-828426932
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/38614)
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/standard-things/esm/issues/821.
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/tc39/ecma262/blob/HEAD/LICENSE.md
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/tc39/ecma262/issues/1209
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/tc39/proposal-iterator-helpers/issues/169
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/tc39/proposal-ses/blob/e5271cc42a257a05dcae2fd94713ed2f46c08620/shim/src/freeze.j
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/tc39/proposal-weakrefs
Source: Wefaceswap.exe, 00000000.00000002.1267017403.000000104EC81000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1241118494.000002A0FF10B000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268192129.0000021A25800000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/vercel/pkg/issues/1589
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://goo.gl/t5IS6M).
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#Replaceable
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#define-the-operations
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#dfn-class-string
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#dfn-default-iterator-object
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#dfn-iterator-prototype-object
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#es-interfaces
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#es-iterable
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#es-iterable-entries
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#es-iterators
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#es-namespaces
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#es-operations
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://heycam.github.io/webidl/#es-stringifier
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/browsers.html#ascii-serialisation-of-an-origin
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/browsers.html#concept-origin-opaque
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/timers-and-user-prompts.html#dom-setinterval
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/webappapis.html#windoworworkerglobalscope
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://infra.spec.whatwg.org/#ascii-whitespace
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://infra.spec.whatwg.org/#forgiving-base64
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://infra.spec.whatwg.org/#forgiving-base64-decode
Source: Wefaceswap.exe, 00000000.00000003.1264150289.000002A0FE987000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://intergenglobal.com/ndfejplsdksuiwnxkahasdnfeqlfej
Source: Wefaceswap.exe, 00000000.00000002.1268001293.000001FBBFA00000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://intergenglobal.com/ndfejplsdksuiwnxkahasdnfeqlfeji
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://invisible-island.net/ncurses/terminfo.ti.html#toc-_Specials
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://jimmy.warting.se/opensource
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://linux.die.net/man/1/dircolors).
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://mathiasbynens.be/notes/javascript-encoding
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://no-color.org/
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://nodejs.org/
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://nodejs.org/api/cli.html#cli_unhandled_rejections_mode).
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://nodejs.org/api/fs.html
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://nodejs.org/api/fs.html#fs_stat_time_values)
Source: Wefaceswap.exe, 00000000.00000002.1277169870.000002DB75F80000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265921102.000002A0FE751000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://nodejs.org/download/release/v18.5.0/node-v18.5.0-headers.tar.gz
Source: Wefaceswap.exe, 00000000.00000003.1266207183.000002A0FE760000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268653208.000002A0FE768000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1266855821.000002A0FE767000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265921102.000002A0FE751000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://nodejs.org/download/release/v18.5.0/node-v18.5.0-headers.tar.gz%
Source: Wefaceswap.exe, 00000000.00000002.1277169870.000002DB75F80000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265921102.000002A0FE751000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268544966.000002A0FE75C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://nodejs.org/download/release/v18.5.0/node-v18.5.0.tar.gz
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://nodejs.org/download/release/v18.5.0/node-v18.5.0.tar.gzhttps://nodejs.org/download/release/v
Source: Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1277169870.000002DB75F80000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265921102.000002A0FE751000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268544966.000002A0FE75C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://nodejs.org/download/release/v18.5.0/win-x64/node.lib
Source: Wefaceswap.exe, 00000000.00000002.1277169870.000002DB75F80000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://nodejs.org/download/release/v18.5.0/win-x64/node.lib1q
Source: Wefaceswap.exe, 00000000.00000003.1266908227.000002A0FE75B000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265921102.000002A0FE751000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268544966.000002A0FE75C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://nodejs.org/download/release/v18.5.0/win-x64/node.lib7
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_chap12.html
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267546654.000000ECDC041000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_chap12.html).
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://sourcemaps.info/spec.html
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://stackoverflow.com/a/5501711/3561
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268042043.0000021383237000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://tc39.es/ecma262/#sec-%typedarray%-intrinsic-object
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://tc39.es/ecma262/#sec-IsHTMLDDA-internal-slot
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://tc39.github.io/ecma262/#sec-%iteratorprototype%-object
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://tc39.github.io/ecma262/#sec-%typedarray%.of
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://tc39.github.io/ecma262/#sec-object.prototype.tostring
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://tools.ietf.org/html/rfc2397#section-2
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://tools.ietf.org/html/rfc3492#section-3.4
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://tools.ietf.org/html/rfc3986#section-3.2.2
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://tools.ietf.org/html/rfc6455#section-1.3
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://tools.ietf.org/html/rfc7230#section-3.2.2
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://tools.ietf.org/html/rfc7230#section-3.2.6
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://tools.ietf.org/html/rfc7540#section-8.1.2.5
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://url.spec.whatwg.org/#cannot-have-a-username-password-port
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://url.spec.whatwg.org/#concept-url
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://url.spec.whatwg.org/#concept-url-origin
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://url.spec.whatwg.org/#concept-urlencoded-byte-serializer
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://url.spec.whatwg.org/#concept-urlencoded-parser
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://url.spec.whatwg.org/#concept-urlencoded-serializer
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267880959.000001C3DBE41000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://url.spec.whatwg.org/#forbidden-host-code-point
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://url.spec.whatwg.org/#special-scheme
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://url.spec.whatwg.org/#url
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://url.spec.whatwg.org/#url-serializing
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://url.spec.whatwg.org/#urlsearchparams
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://url.spec.whatwg.org/#urlsearchparams-stringification-behavior
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://v8.dev/blog/v8-release-89
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://w3c.github.io/resource-timing/#dfn-mark-resource-timing
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276516899.000002A8A25C1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://w3c.github.io/resource-timing/#dfn-setup-the-resource-timing-entry
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://w3c.github.io/webappsec-subresource-integrity/#the-integrity-attribute
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://webassembly.github.io/spec/web-api
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://wiki.squid-cache.org/SquidFaq/InnerWorkings#What_is_a_half-closed_filedescriptor.3F
Source: Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF551000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1271945640.000002A0FF1FE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.catcert.net/verarrel
Source: Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF4BC000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF4E2000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF4E3000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF4E1000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1243407227.000002A0FF551000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.catcert.net/verarrel05
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/#sec-line-terminators
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1276564433.000002D269281000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1268042043.0000021383237000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/#sec-promise.all
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/#sec-timeclip
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1267586668.000001776DB81000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/5.1/#sec-15.1.3.4
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-Alternative
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-Atom
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-CharacterClass
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-CharacterClassEscape
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-ClassAtom
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-ClassAtomNoDash
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-ClassRanges
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-ControlEscape
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-ControlLetter
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-DecimalDigits
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-DecimalEscape
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-Disjunction
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-Hex4Digits
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-HexDigit
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-HexDigits
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-HexEscapeSequence
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-NonemptyClassRanges
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-NonemptyClassRangesNoDash
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-OctalDigit
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-Pattern
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-PatternCharacter
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-Quantifier
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-QuantifierPrefix
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-RegExpUnicodeEscapeSequence
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-SyntaxCharacter
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-Assertion
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-AtomEscape
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-CharacterEscape
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-ClassControlLetter
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-ClassEscape
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-ExtendedAtom
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-ExtendedPatternCharacter
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-IdentityEscape
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-InvalidBracedQuantifier
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-LegacyOctalEscapeSequence
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-Term
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#sec-atomescape
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.ecma-international.org/ecma-262/8.0/#sec-term
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.iana.org/assignments/tls-extensiontype-values
Source: Wefaceswap.exe, 00000000.00000000.1236591413.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp, Wefaceswap.exe, 00000000.00000003.1240113431.000002A0FF235000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1277470882.00000358E86C1000.00000004.00001000.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.unicode.org/Public/UNIDATA/EastAsianWidth.txt
Source: Wefaceswap.exe, 00000000.00000002.1272882607.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264162883.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1264823661.000002A0FF52F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://wwww.certigna.fr/autorites/
Source: Wefaceswap.exe, 00000000.00000003.1263416712.000002A0FF089000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263567180.000002A0FF0CB000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263255097.000002A0FF038000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1263792363.000002A0FF0D5000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1265680611.000002A0FF102000.00000004.00000020.00020000.00000000.sdmp, Wefaceswap.exe, 00000000.00000003.1262889886.000002A0FF031000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://wwww.certigna.fr/autorites/0m
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: Wefaceswap.exe, 00000000.00000002.1282700173.00007FF7F8F8A000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameWefacesawap.exeD vs Wefaceswap.exe
Source: classification engine Classification label: clean16.winEXE@1/1@1/1
Source: C:\Users\user\Desktop\Wefaceswap.exe File created: C:\Users\user\AppData\Local\HLaHSnryez Jump to behavior
Source: Wefaceswap.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Wefaceswap.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe File read: C:\Users\user\Desktop\Wefaceswap.exe Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: Wefaceswap.exe Static PE information: certificate valid
Source: Wefaceswap.exe Static PE information: More than 8191 > 100 exports found
Source: Wefaceswap.exe Static PE information: Virtual size of .text is bigger than: 0x100000
Source: Wefaceswap.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: Wefaceswap.exe Static file information: File size 37887136 > 1048576
Source: Wefaceswap.exe Static PE information: Raw size of .text is bigger than: 0x100000 < 0x12aa000
Source: Wefaceswap.exe Static PE information: Raw size of .rdata is bigger than: 0x100000 < 0xfe5c00
Source: Wefaceswap.exe Static PE information: More than 200 imports for KERNEL32.dll
Source: Wefaceswap.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: Wefaceswap.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: Wefaceswap.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: Wefaceswap.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Wefaceswap.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: Wefaceswap.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: Wefaceswap.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Wefaceswap.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\Users\runneradmin\AppData\Local\Temp\pkg.24e0b2b2d51e47b9dba34c30\node\out\Release\node.pdb\ source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F86CB000.00000002.00000001.01000000.00000003.sdmp
Source: Binary string: C:\Users\runneradmin\AppData\Local\Temp\pkg.24e0b2b2d51e47b9dba34c30\node\out\Release\node.pdb source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F86CB000.00000002.00000001.01000000.00000003.sdmp
Source: Wefaceswap.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: Wefaceswap.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: Wefaceswap.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: Wefaceswap.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: Wefaceswap.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: Wefaceswap.exe Static PE information: section name: _RDATA
Source: C:\Users\user\Desktop\Wefaceswap.exe Code function: 0_2_00007FF7778888DA push es; ret 0_2_00007FF7778888DB
Source: C:\Users\user\Desktop\Wefaceswap.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: Wefaceswap.exe, 00000000.00000002.1268325498.000002A0FE722000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW2
Source: Wefaceswap.exe, 00000000.00000002.1268325498.000002A0FE722000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: Wefaceswap.exe, 00000000.00000002.1280274259.00007FF7F7CCB000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: lgnW2/4/PEZB31jiVg88O8EckzXZOFKs7sjsLjBOlDW0JB9LeGna8gI4zJVSk/BwJVmcIGfE
Source: C:\Users\user\Desktop\Wefaceswap.exe Queries volume information: C:\Users\user\Desktop\Wefaceswap.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Queries volume information: C:\Users\user\AppData\Local VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Wefaceswap.exe Queries volume information: C:\Users\user\AppData\Local\HLaHSnryez VolumeInformation Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs