Windows Analysis Report
file.exe

Overview

General Information

Sample name: file.exe
Analysis ID: 1540234
MD5: af3d3fda1b3964c834c3f6a5d63862e8
SHA1: 550a8e43a1cca0c21bf5b2a5bafe2a0236dae923
SHA256: 6a2ff07c761f66b225d113d7fde579361e4b10e8770d97d734fe92940592a618
Tags: exeuser-jstrosch
Infos:

Detection

Score: 22
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Compliance

Score: 49
Range: 0 - 100

Signatures

Java source code contains very large array initializations
Contains functionality to dynamically determine API calls
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
PE file contains an invalid checksum
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Queries the volume information (name, serial number etc) of a device
Queries time zone information
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Compliance

barindex
Source: file.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\install.log Jump to behavior
Source: file.exe Static PE information: certificate valid
Source: C:\Users\user\Desktop\file.exe File opened: C:\HamSphere\HamSphere_4.010a\rt\bin\msvcr100.dll Jump to behavior
Source: file.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.dc\dcpr\obj\dcpr.pdbi source: file.exe, 00000000.00000003.1708854994.0000000003B75000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1708414729.0000000003314000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\java.net\net\obj\net.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2660623950.000000006E6EC000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.font\fontmanager\obj\fontmanager.pdbB source: HamSphere_4.010a.exe, 00000004.00000002.2661725192.000000006FE3E000.00000002.00000001.01000000.00000016.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.font\t2k\obj\t2k.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2661557817.000000006FE17000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\java.net\net\obj\net.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2660623950.000000006E6EC000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\java\java.nio\nio\obj\nio.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2661993669.0000000073977000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.dc\dcpr\obj\dcpr.pdb source: file.exe, 00000000.00000003.1708854994.0000000003B75000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1708414729.0000000003314000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.awt\jpeg\obj\jpeg.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2661323813.000000006FD9E000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.awt\awt\obj\awt.pdb source: file.exe, 00000000.00000003.1708854994.0000000003B75000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1708414729.0000000003314000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.awt\awt\obj\awt.pdbp source: file.exe, 00000000.00000003.1708854994.0000000003B75000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1708414729.0000000003314000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.font\fontmanager\obj\fontmanager.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2661725192.000000006FE3E000.00000002.00000001.01000000.00000016.sdmp
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_00410110 GetModuleHandleA,FindFirstFileA,FindClose,FindFirstFileA,FindClose,LoadLibraryA,GetProcAddress,GetProcAddress, 4_2_00410110
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_0040F460 FindFirstFileA,FindClose, 4_2_0040F460
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_0040D7F0 FindFirstFileA,GetProcessHeap,HeapAlloc,FindNextFileA,FindClose, 4_2_0040D7F0
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_02396110 EntryPoint,DisableThreadLibraryCalls,GetModuleHandleA,FindFirstFileA,FindClose,FindFirstFileA,FindClose,LoadLibraryA,GetProcAddress,GetProcAddress, 4_2_02396110
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_02396710 FindFirstFileA,FindClose, 4_2_02396710
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_071B1740 FindFirstFileA,FindClose, 4_2_071B1740
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+08h] 4_2_0048405D
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_004480F4
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push edi 4_2_0045A084
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_00482170
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_00482170
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_0043C1E1
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_0044F1C3
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push 004B9AF8h 4_2_004471F4
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then add esp, FFFFFFF4h 4_2_00447184
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_004472E4
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_0044D294
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_00447314
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_0041B480
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_0043B674
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then add esp, FFFFFFF4h 4_2_0043B744
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_0042B730
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_0047F730
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_0047F7DD
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebx 4_2_0043B7A4
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push 004BAA68h 4_2_0040B8A6
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push 004B73E8h 4_2_004259EF
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_0046F985
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_00441A54
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_0046FA64
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_0043BA22
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_00443AC4
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_00443A94
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_00443B34
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_00443BE4
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_0041BB8F
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_0040BC45
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_00443C54
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_00447C04
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push 004B96B0h 4_2_00443E64
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+08h] 4_2_00483E3E
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_0045BF75
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_00443F04
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push 024A6998h 4_2_021FB21F
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_02208256
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then add esp, FFFFFFF4h 4_2_021EC264
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push edi 4_2_022082A4
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push edi 4_2_0220A2A5
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then xor eax, eax 4_2_021E4290
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [024C9498h] 4_2_021EC2A4
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+10h] 4_2_02214343
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_021EA3D4
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_021EC104
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then add esp, FFFFFFF4h 4_2_0220B140
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then add esp, FFFFFFF0h 4_2_0220B140
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then add esp, FFFFFFF0h 4_2_0220B140
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then add esp, FFFFFFF4h 4_2_0220B140
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push esi 4_2_021E9164
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push esi 4_2_02210195
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [024C9494h] 4_2_021EC1DC
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push 024A6998h 4_2_021FB1CC
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [024C9494h] 4_2_021EC1FE
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push 024A58E8h 4_2_021F3610
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebx 4_2_02201605
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push esi 4_2_021F9673
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_02200754
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+0Ch] 4_2_021EA40D
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+0Ch] 4_2_021ED484
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push 024A3C90h 4_2_021E7575
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push 024A7088h 4_2_021FF594
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push 024A58E8h 4_2_021F3590
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_021F45AF
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_021E2A44
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_02200A84
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_021E9AE5
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_071CFF65
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_071BEFA6
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 4_2_071C1E4C
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push eax 4_2_071BFEC9
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebx 4_2_071C9D0B
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebx 4_2_071C9F41
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebx 4_2_071C9F97
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebx 4_2_071C9FED
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebx 4_2_071C9E4B
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebx 4_2_071C9E9B
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebx 4_2_071C9EEB
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4x nop then push ebp 4_2_0042004E
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /antennas.php HTTP/1.1User-Agent: Java/1.7.0_55Host: hs4.hamsphere.comAccept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2Connection: keep-alive
Source: global traffic HTTP traffic detected: GET /news40.php HTTP/1.1User-Agent: Java/1.7.0_55Host: hs4.hamsphere.comAccept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2Connection: keep-alive
Source: global traffic HTTP traffic detected: GET /images/hs5logo.jpg HTTP/1.1User-Agent: Java/1.7.0_55Host: hs40.hamsphere.comAccept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2Connection: keep-alive
Source: global traffic DNS traffic detected: DNS query: 241.42.69.40.in-addr.arpa
Source: global traffic DNS traffic detected: DNS query: hs4.hamsphere.com
Source: global traffic DNS traffic detected: DNS query: hs40.hamsphere.com
Source: unknown HTTP traffic detected: POST /getremotenames.php HTTP/1.1User-Agent: Java/1.7.0_55Host: hs4.hamsphere.comAccept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2Connection: keep-aliveContent-type: application/x-www-form-urlencodedContent-Length: 3
Source: HamSphere_4.010a.exe String found in binary or memory: http://NAK:plugins/plugins.graphics/hspl_led_big_red.pngPING:3.0addURL./pluginsCaptur
Source: HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://NAK:plugins/plugins.graphics/hspl_led_big_red.pngPING:3.0addURL./pluginsCaptureISO-8859-1http
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/allow-java-encodingscreateMessage
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/continue-after-fatal-errorSintaxe
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/create-cdata-nodesoptionXXoptionXTAsserzione
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/disallow-doctype-decl
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/disallow-doctype-declIl
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/dom/create-entity-ref-nodesER_CANNOT_CMPL_EXTENSNbaseenvelopedSignatu
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/dom/defer-node-expansion
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/dom/include-ignorable-whitespaceThe
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/feature-read-only$
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/generate-synthetic-annotationsInputStream
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/honour-all-schemaLocationsNamespace-URI
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/include-comments
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/internal/parser-settingsM
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/internal/tolerate-duplicatesXMLReader
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/internal/validation/schema/use-grammar-pool-onlySubstitut
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/namespace-growthdetach()
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/namespacesAbfragezeichenfolge
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/nonvalidating/load-external-dtdXalan:
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/scanner/notify-builtin-refsNom
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/scanner/notify-char-refs
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/standard-uri-conformantThe
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validate-annotationsN
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validation/balance-syntax-treesxsltc.jar<
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validation/dynamicEXPRTOKEN_CLOSE_PAREN(StylesheetHandler)
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema-full-checking
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema/augment-psvi(StylesheetHandler)
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema/element-defaultgenerate-translet
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema/normalized-valueApache
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schemaElement
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validation/warn-on-duplicate-attdef
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validation/warn-on-undeclared-elemdefErforderliches
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/validationCurrency
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/xinclude
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/xinclude/fixup-base-urisgetNextSiblingn0DTMg0OUL
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/features/xinclude/fixup-languageTentative
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/La
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/dom/current-element-nodeCyrillicWG_ENCODING_NOT_SUPPORTED_USING_JAV
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/dom/document-class-nameexclude-result-prefixesX
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/input-buffer-size$aster$Ergebnis
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/datatype-validator-factorysystemSuffixN.
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/document-scannercause
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/dtd-processor
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/entity-managerNombre
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/entity-resolverImpossible
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/error-handlerXSLTC
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/error-reporterjavax.xml.stream.XMLInputFactoryER_BAD_STYLE
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/grammar-poolyesXPath
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/namespace-binderIO
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/namespace-contextCreazione
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/stax-entity-resolverOgiltigt
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/symbol-table
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/symbol-tablehrefIllegal
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validation-managerAES/CBC/ISO10126PaddingThirty-SevenFalha
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validation/schema/dv-factorygetChildren
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validator/dtdxmlStructure
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validator/schemaDeprecated
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/xinclude-handlerAV
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/xpointer-handlerxml:space
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/localeJAXP
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/schema/external-noNamespaceSchemaLocationER_XMLRDR_NOT_BEFORE_START
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/schema/external-schemaLocation(StylesheetHandler)
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/security-managerV
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/xpointer-schema
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/xpointer-schema.
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/properties/xpointer-schemaCannot
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/serializerSYNTAXE
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://apache.org/xml/xmlschema/1.0/anonymousTypesSe
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cps.chambersign.org/cps/chambersroot.html0
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.certum.pl/ca.crl0:
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.certum.pl/ctnca.crl0
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.chambersign.org/chambersroot.crl0
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: file.exe, 00000000.00000003.1647838320.0000000004D81000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625575967.0000000006B08000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625431850.00000000069F2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625695568.00000000061EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
Source: file.exe, 00000000.00000003.1647838320.0000000004D81000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625575967.0000000006B08000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625431850.00000000069F2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625695568.00000000061EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://exslt.org/common
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://exslt.org/common:nodeSetIl
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://exslt.org/common:objectTypeEBCDIC-CP-ROECEdoctype-publicboolean(...)
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://exslt.org/dates-and-timesLcom/sun/org/apache/xalan/internal/xsltc/dom/DOMAdapter;Could
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://exslt.org/dynamicappendhttp://xml.org/sax/features/string-interningDans
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://exslt.org/functionsIntern
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://exslt.org/math
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://exslt.org/setsAttribute
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://exslt.org/stringsXalan:
Source: HamSphere_4.010a.exe String found in binary or memory: http://hs4.hamsphere.com/antennas.php/skins/120C96d5C1plain_blackhttp://hs4.hamsphere.com/getremoten
Source: HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://hs4.hamsphere.com/copyremoterig.phpunderlineInterrupted15mipError:
Source: HamSphere_4.010a.exe, HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://hs4.hamsphere.com/deleteremoterig.phpgraphics/hspl_led_medium_red.pngfmt
Source: HamSphere_4.010a.exe String found in binary or memory: http://hs4.hamsphere.com/ge
Source: HamSphere_4.010a.exe, HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://hs4.hamsphere.com/getrandomserver.php?callsign="combographics/hspl_led_small_yellow.pngh
Source: HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://hs4.hamsphere.com/getremoterig.php3154BDA62539DC66SPEEX_VBR_quality_7graphics/hspl_medium_but
Source: HamSphere_4.010a.exe, HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://hs4.hamsphere.com/getremotesettings.phpInvalid
Source: HamSphere_4.010a.exe, HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1754899830.00000000167CC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://hs4.hamsphere.com/news40.php
Source: HamSphere_4.010a.exe, HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://hs4.hamsphere.com/posterror.php'Insufficient
Source: HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://hs4.hamsphere.com/renameremoterig.php4.010aLSBENTmozilla
Source: HamSphere_4.010a.exe, HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://hs4.hamsphere.com/saveremoterig.phpUSBshCorrupt
Source: HamSphere_4.010a.exe, HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://hs4.hamsphere.com/saveremotesettings.phpServer
Source: HamSphere_4.010a.exe, 00000004.00000002.2656388178.000000001658C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://hs40.hamsphere.com
Source: HamSphere_4.010a.exe, 00000004.00000002.2642887092.0000000004D22000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2642626722.0000000004CD6000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2640808641.00000000040A2000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2656388178.000000001657C000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1754427496.0000000004CD6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://hs40.hamsphere.com/images/hs5logo.jpg
Source: HamSphere_4.010a.exe, 00000004.00000002.2648927578.000000001327E000.00000008.00000001.01000000.0000000A.sdmp String found in binary or memory: http://java.sun.com/dtd/preferences.dtd.
Source: HamSphere_4.010a.exe, 00000004.00000002.2648927578.000000001327E000.00000008.00000001.01000000.0000000A.sdmp String found in binary or memory: http://java.sun.com/dtd/properties.dtdartsetcbokngetKDCFromDNS
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/j2se/1.6.0/docs/guide/standards/)
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/jaxp/xpath/dom
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/jaxp/xpath/domAssertion
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/dom/properties/ancestor-checkScheme
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/jaxp/properties/XMLDSig
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/jaxp/properties/schemaLanguageaxe
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/jaxp/properties/schemaSource
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/jaxp/properties/schemaSourceYou
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/schema/features/MSG_MORE_THAN_ONE_NOTATION_ATTRIBUTESecurityException
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/schema/features/report-ignored-element-content-whitespaceEn
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/stream/properties/CipherData.getDataType()
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/stream/properties/ignore-external-dtdparser.atom.4
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/stream/properties/reader-in-defined-state
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://java.sun.com/xml/stream/properties/report-cdata-event_sTypesArray(Z)ZCodifica
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.XMLConstants/feature/secure-processingPUTjavax.xml.soap.SOAPConnectionFactory
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/Tento
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/accessExternalDTDFailed
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/accessExternalSchemaKunde
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/accessExternalStylesheetNo
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.transform.dom.DOMResult/featureObjet
Source: HamSphere_4.010a.exe, 00000004.00000002.2648927578.000000001327E000.00000008.00000001.01000000.0000000A.sdmp String found in binary or memory: http://javax.xml.transform.dom.DOMSource/featureJIT
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.transform.dom.DOMSource/featurez
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.transform.sax.SAXSource/featureOgiltigt
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.transform.sax.SAXTransformerFactory/feature/xmlfilter
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.transform.sax.SAXTransformerFactory/featureCould
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.transform.stax.StAXResult/featureInvalid
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.transform.stax.StAXSource/feature
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.transform.stream.StreamResult/featureSe
Source: HamSphere_4.010a.exe, 00000004.00000002.2648927578.000000001327E000.00000008.00000001.01000000.0000000A.sdmp String found in binary or memory: http://javax.xml.transform.stream.StreamResult/featuredoAsPrivilegedCARIansi_x3.4-1968amurskinvalid
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://javax.xml.transform.stream.StreamSource/featurefconstElaborazione
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://jaxb.dev.java.net/arraymessage.nullEncodingAlgorithmURIelementGetText()
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://jvnet.org/fastinfoset/parser/properties/buffer-sizeNull
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://jvnet.org/fastinfoset/parser/properties/external-vocabulariesprefix/:
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://jvnet.org/fastinfoset/parser/properties/force-stream-closereadOnce()
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://jvnet.org/fastinfoset/parser/properties/registered-encoding-algorithmslocalNameCouldn
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://jvnet.org/fastinfoset/parser/properties/string-interningfaultcodefalseMS932UNRESOLVED_IDREFSA
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://jvnet.org/fastinfoset/sax/properties/primitive-type-content-handlermessage.unexpectedEventTyp
Source: HamSphere_4.010a.exe, 00000004.00000002.2648927578.000000001327E000.00000008.00000001.01000000.0000000A.sdmp String found in binary or memory: http://null.sun.com//Library/Preferences/edu.mit.Kerberosnull
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://nwalsh.com/xcatalog/1.0///
Source: file.exe, 00000000.00000003.1647838320.0000000004D81000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625575967.0000000006B08000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625431850.00000000069F2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625695568.00000000061EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0
Source: file.exe, 00000000.00000003.1647838320.0000000004D81000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625575967.0000000006B08000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625431850.00000000069F2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1625695568.00000000061EE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0$
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1726548197.00000000040B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ocsp.example.net:80
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://policy.camerfirma.com0
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://repository.certum.pl/ctnca.cer0/
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://repository.swisssign.com/0
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/drem
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/-Xalan(u
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/versioncom.sun.xml.internal.bind.xmlHeadersgotomessage.deco
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/security/2000-12ChunkedIntArray(
Source: HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://shop.hamsphere.com/advanced_search_result.php?keywords=ANT
Source: HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://shop.hamsphere.com/advanced_search_result.php?keywords=Select
Source: HamSphere_4.010a.exe, HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://shop.hamsphere.comASSEMBLY(1):
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ws-i.org/profiles/basic/1.1/swaref.xsdcom.sun.xml.internal.messaging.saaj.soap.ver1_1--%M-%D%
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.alphaworks.ibm.com/formula/xml
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.alphaworks.ibm.com/formula/xml(StylesheetHandler)
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.alphaworks.ibm.com/formula/xml/
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.alphaworks.ibm.com/formula/xmlARCHIVEotherwisefind
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.alphaworks.ibm.com/formula/xmlER_NODESET_NOT_MUTABLEaddAttribute1697-02-01T00:00:00ZgetDe
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.alphaworks.ibm.com/formula/xmlJAXP:
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.alphaworks.ibm.com/formula/xmlNull
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.alphaworks.ibm.com/formula/xmlPath
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.alphaworks.ibm.com/formula/xmlunsignedLongXRTreeFragSelectWrapper
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.certicom.com/2000/11/xmlecdsig#ecdsa-sha1XPTRTOKEN_ELEM_NCNAMEL
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.chambersign.org1
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.entrust.net/CRL/net1.crl0
Source: HamSphere_4.010a.exe, 00000004.00000002.2648613254.0000000013277000.00000004.00000001.01000000.0000000A.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2656388178.0000000016560000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2636523787.0000000000643000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.excelsior-usa.com
Source: HamSphere_4.010a.exe, 00000004.00000002.2648927578.000000001327E000.00000008.00000001.01000000.0000000A.sdmp String found in binary or memory: http://www.excelsior-usa.comUnknown
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.0000000000643000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.excelsior-usa.coma
Source: HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp String found in binary or memory: http://www.excelsior-usa.comjava.vendor.urlSun-Oracle
Source: HamSphere_4.010a.exe, 00000004.00000002.2648613254.0000000013277000.00000004.00000001.01000000.0000000A.sdmp String found in binary or memory: http://www.excelsior-usa.comxrJavaProp.modunknown
Source: HamSphere_4.010a.exe, HamSphere_4.010a.exe, 00000004.00000002.2636193890.00000000004A0000.00000004.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.hamsphere.com/registertheorderLOGIN_ERROR&newname=idError
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ibm.com/Bad
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ietf.org/internet-drafts/draft-eastlake-xmldsig-uri-02.txt
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ietf.org/rfc/rfc2373.txt)
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.isi.edu/in-notes/iana/assignments/media-types/internal/error-handlerAppel
Source: file.exe, 00000000.00000003.1625695568.00000000067EA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.mozilla.org/MPL/
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.nue.et-inf.uni-siegen.de/~geuer-pollmann/#xpathFilter
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.nue.et-inf.uni-siegen.de/~geuer-pollmann/#xpathFilteranalyse
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oasis-open.org/committees/entity/release/1.0/catalog.dtdFragment
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oasis-open.org/committees/entity/release/1.0/catalog.rng
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oasis-open.org/committees/entity/release/1.0/catalog.xsd-//W3C//DTD
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/feature/use-service-mechanism(annotation?
Source: HamSphere_4.010a.exe, 00000004.00000002.2637397487.000000000241A000.00000008.00000001.01000000.0000000C.sdmp String found in binary or memory: http://www.oracle.com/technetwork/java/javase/documentation/index.html
Source: HamSphere_4.010a.exe, 00000004.00000002.2637397487.000000000241A000.00000008.00000001.01000000.0000000C.sdmp String found in binary or memory: http://www.oracle.com/technetwork/java/javase/documentation/index.html.Africa/Luandafriulanoaymar
Source: HamSphere_4.010a.exe, 00000004.00000002.2637397487.000000000241A000.00000008.00000001.01000000.0000000C.sdmp String found in binary or memory: http://www.oracle.com/technetwork/java/javase/documentation/index.html.pashtoAustralia/QueenslandTon
Source: HamSphere_4.010a.exe, 00000004.00000002.2637397487.000000000241A000.00000008.00000001.01000000.0000000C.sdmp String found in binary or memory: http://www.oracle.com/technetwork/java/javase/documentation/index.htmlD
Source: HamSphere_4.010a.exe, 00000004.00000002.2637397487.000000000241A000.00000008.00000001.01000000.0000000C.sdmp String found in binary or memory: http://www.oracle.com/technetwork/java/javase/documentation/index.htmlDollaro
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/is-standaloneError
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/elementAttributeLimitFilterParentPath(
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/entityExpansionLimitE-CfenvironmentDDCcNo
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/getEntityCountInfo
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/maxGeneralEntitySizeLimitunsignedByteSe
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/maxOccurLimitNezn
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/maxParameterEntitySizeLimitLe
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/maxXMLNameLimitparser.factor.0((##any
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/system-propertyER_COULD_NOT_RESOLVE_NODEorg.w3c.dom.xpath.
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/totalEntitySizeLimit___multiple_node_counter
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/xmlSecurityPropertyManagerjava/text/Collator
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.quovadis.bm0
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.quovadisglobal.com/cps0
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.sun.com/xml/sax-events
Source: HamSphere_4.010a.exe, 00000004.00000003.1754115294.0000000016864000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2656388178.000000001684C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.tiro.comMicrosoft
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.trustcenter.de/crl/v2/tc_class_2_ca_II.crl
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.valicert.com/1
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.xmlsecurity.org/NS/#configuration
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.xmlsecurity.org/experimental#
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.xmlsecurity.org/experimental#xstr()
Source: HamSphere_4.010a.exe, 00000004.00000003.1754115294.0000000016864000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.zhongyicts.com.cn
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.apache.org/xalan-j
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan-j/faq.html
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan-jNot
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan/PipeDocumentIl
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan/features/incremental
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan/features/incrementalD
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan/features/optimize
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan/java
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan/psuedovarhttp://apache.org/xml/features/warn-on-duplicate-entitydefError
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan/sql
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan/xsltc/javacvc-enumeration-validErreur
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan/xsltcISO-IR-149ISO-IR-148ISO-IR-144DTMLiaison
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xalan:nodesetXRTreeFragSelectWrapper
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xpath/features/whitespace-pre-strippingRecursiveIncludehexBinary
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xslt
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xslt/javaISO_8859-3ISO_8859-2ResolverISO_8859-1Errore
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.org/xsltN
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.apache.orggoto_w
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/features/allow-dtd-events-after-endDTDEmpty
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/external-general-entities.
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/features/external-general-entitiesImpossible
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/external-parameter-entities2.1Can
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/features/external-parameter-entitiesdigestValue
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/features/namespace-prefixes
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/namespace-prefixesxop
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/features/namespacesCe
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/namespacesappendFaultSubcodeBYTEEntity
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/features/string-interningfeature
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/features/true-not-supported
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/features/use-entity-resolver2com.sun.org.apache.xerces.internal.impl.dv.dtd.XML11
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/features/validationAxis
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/features/xmlns-urisnulln0P
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/properties/declaration-handlerusing
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/properties/dom-nodeER_STARTPARSE_WHILE_PARSINGt
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/properties/lexical-handlerSystemId-Unknown:locator-unavailable:
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xml.org/sax/properties/xml-stringSe
Source: HamSphere_4.010a.exe, 00000004.00000002.2638264849.0000000002B20000.00000008.00000001.01000000.0000000E.sdmp String found in binary or memory: http://xsl.lotus.com/javaInternal
Source: HamSphere_4.010a.exe, 00000004.00000002.2656388178.00000000167CC000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2642626722.0000000004CD6000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2656388178.00000000165A0000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2640808641.00000000040A2000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1754427496.0000000004CD6000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2656388178.0000000016824000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1754899830.00000000167CC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://hs50.hamsphere.com/?external
Source: HamSphere_4.010a.exe, 00000004.00000002.2656388178.000000001658C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://hs50.hamsphere.com/?externalb
Source: HamSphere_4.010a.exe, 00000004.00000002.2656388178.000000001658C000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2656388178.00000000167CC000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2642626722.0000000004CD6000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2640808641.00000000040A2000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1754427496.0000000004CD6000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2656388178.0000000016824000.00000004.00001000.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1754899830.00000000167CC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://hs50.hamsphere.com?external
Source: HamSphere_4.010a.exe, 00000004.00000002.2656388178.0000000016824000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://hs50.hamsphere.com?external8
Source: HamSphere_4.010a.exe, 00000004.00000002.2656388178.00000000167CC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://hs50.hamsphere.com?externall
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://ocsp.quovadisoffshore.com0
Source: file.exe, 00000000.00000003.1625695568.0000000006260000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.certum.pl/CPS0

System Summary

barindex
Source: sunmscapi.jar.0.dr, com/sun/crypto/provider/BlowfishCrypt.java Large array initialization: F: array initializer size 1042
Source: sunpkcs11.jar.0.dr, com/sun/crypto/provider/BlowfishCrypt.java Large array initialization: F: array initializer size 1042
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_00482170 4_2_00482170
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_00481500 4_2_00481500
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_004619E0 4_2_004619E0
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_00475CC8 4_2_00475CC8
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_00473D00 4_2_00473D00
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_0045FD20 4_2_0045FD20
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_0047984B 4_2_0047984B
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_0046957E 4_2_0046957E
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: String function: 021E136C appears 51 times
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: String function: 00485E1C appears 82 times
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: String function: 00485DA4 appears 33 times
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: String function: 021E134E appears 199 times
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: String function: 073FDD8E appears 31 times
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: String function: 00485D26 appears 58 times
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: String function: 00485DFE appears 159 times
Source: XKRN10505.dll.0.dr Static PE information: Number of sections : 11 > 10
Source: userinstall.dll.0.dr Static PE information: No import functions for PE file found
Source: file.exe, 00000000.00000003.1708854994.0000000003B75000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameawt.dllV vs file.exe
Source: file.exe, 00000000.00000003.1708414729.0000000003314000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameawt.dllV vs file.exe
Source: file.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engine Classification label: sus22.winEXE@3/108@3/1
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Mutant created: NULL
Source: C:\Users\user\Desktop\file.exe File created: C:\Users\user\AppData\Local\Temp\xnsE6A3.tmp Jump to behavior
Source: file.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\file.exe File read: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\file.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\file.exe File read: C:\Users\user\Desktop\file.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
Source: C:\Users\user\Desktop\file.exe Process created: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe "C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe"
Source: C:\Users\user\Desktop\file.exe Process created: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe "C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe" Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: winmm.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: pdh.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: perfos.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: wldp.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: wldp.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: profapi.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\file.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\file.exe Automated click: Next >
Source: C:\Users\user\Desktop\file.exe Automated click: Next >
Source: C:\Users\user\Desktop\file.exe Automated click: Next >
Source: C:\Users\user\Desktop\file.exe Automated click: Next >
Source: C:\Users\user\Desktop\file.exe Automated click: Next >
Source: file.exe Static PE information: certificate valid
Source: file.exe Static file information: File size 24973736 > 1048576
Source: C:\Users\user\Desktop\file.exe File opened: C:\HamSphere\HamSphere_4.010a\rt\bin\msvcr100.dll Jump to behavior
Source: file.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.dc\dcpr\obj\dcpr.pdbi source: file.exe, 00000000.00000003.1708854994.0000000003B75000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1708414729.0000000003314000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\java.net\net\obj\net.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2660623950.000000006E6EC000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.font\fontmanager\obj\fontmanager.pdbB source: HamSphere_4.010a.exe, 00000004.00000002.2661725192.000000006FE3E000.00000002.00000001.01000000.00000016.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.font\t2k\obj\t2k.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2661557817.000000006FE17000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\java.net\net\obj\net.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2660623950.000000006E6EC000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\java\java.nio\nio\obj\nio.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2661993669.0000000073977000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.dc\dcpr\obj\dcpr.pdb source: file.exe, 00000000.00000003.1708854994.0000000003B75000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1708414729.0000000003314000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.awt\jpeg\obj\jpeg.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2661323813.000000006FD9E000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.awt\awt\obj\awt.pdb source: file.exe, 00000000.00000003.1708854994.0000000003B75000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1708414729.0000000003314000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.awt\awt\obj\awt.pdbp source: file.exe, 00000000.00000003.1708854994.0000000003B75000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1708414729.0000000003314000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\build_area\1.7.0_55\hs_build\tmp\sun\sun.font\fontmanager\obj\fontmanager.pdb source: HamSphere_4.010a.exe, 00000004.00000002.2661725192.000000006FE3E000.00000002.00000001.01000000.00000016.sdmp
Source: C:\Users\user\Desktop\file.exe Code function: 0_2_00FC185E EntryPoint,lstrcmpA,lstrcmpA,lstrcmpA,CloseHandle,CloseHandle,CloseHandle,LoadLibraryA,GetProcAddress,FreeLibrary,FreeLibrary,ExitProcess, 0_2_00FC185E
Source: sunmscapi.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x5082
Source: jsound.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x11334
Source: w2k_lsa_auth.dll.0.dr Static PE information: real checksum: 0x0 should be: 0xfef3
Source: XJCE10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x85562
Source: JavaAccessBridge-32.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x28d26
Source: JAWTAccessBridge-32.dll.0.dr Static PE information: real checksum: 0x0 should be: 0xaa25
Source: WindowsAccessBridge-32.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x1cd98
Source: jvm.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x679b
Source: XIMG10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x2cd24
Source: XMSC10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x20017
Source: XSQL10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x92dff
Source: jpeg.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x23f97
Source: dcpr.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x2cfc6
Source: HamSphere_4.010a.exe.0.dr Static PE information: real checksum: 0x1a2ef7 should be: 0x198488
Source: XCRB10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x5ab001
Source: xjitb_j10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x39e6a5
Source: sunec.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x23431
Source: t2k.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x343ee
Source: net.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x1a38f
Source: XSEC10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x1ca59a
Source: XPKC10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x8801b
Source: XXWS10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x2a7238
Source: XMIS10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x3a8d6c
Source: fontmanager.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x3a6ef
Source: XSWN10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x2417d4
Source: unpack.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x105e6
Source: nio.dll.0.dr Static PE information: real checksum: 0x0 should be: 0xf2bc
Source: java.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x193d2
Source: XSND10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x110c66
Source: jawt.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x9e76
Source: Uninstall.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x6aeea
Source: XINV10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x1ecf1
Source: XMIA10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x17ef35
Source: j2pkcs11.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x14d2f
Source: XSCR10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x153055
Source: xnsE6A3.tmp.0.dr Static PE information: real checksum: 0x0 should be: 0xc63a5
Source: cleanup.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x1b1d4
Source: mlib_image.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x968e0
Source: XRMI10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x4bbac
Source: jaas_nt.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x4db6
Source: XEND10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x13ef3
Source: XXXL10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x2f9ab4
Source: XSSE10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0xba81d
Source: kcms.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x32f11
Source: zip.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x17219
Source: XMNG10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x17ad52
Source: XXML10505.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x8c4f22
Source: awt.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x11df1d
Source: userinstall.dll.0.dr Static PE information: real checksum: 0x0 should be: 0xe03b
Source: JdbcOdbc.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x9b0d
Source: j2pcsc.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x41c1
Source: jsoundds.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x13083
Source: XAWT10505.dll.0.dr Static PE information: section name: .jidata
Source: XAWT10505.dll.0.dr Static PE information: section name: .jedata
Source: XAWT10505.dll.0.dr Static PE information: section name: .config
Source: XCRB10505.dll.0.dr Static PE information: section name: .jidata
Source: XCRB10505.dll.0.dr Static PE information: section name: .jedata
Source: XCRB10505.dll.0.dr Static PE information: section name: .config
Source: XEND10505.dll.0.dr Static PE information: section name: .jidata
Source: XEND10505.dll.0.dr Static PE information: section name: .jedata
Source: XEND10505.dll.0.dr Static PE information: section name: .config
Source: XIMG10505.dll.0.dr Static PE information: section name: .jidata
Source: XIMG10505.dll.0.dr Static PE information: section name: .jedata
Source: XIMG10505.dll.0.dr Static PE information: section name: .config
Source: XINV10505.dll.0.dr Static PE information: section name: .jidata
Source: XINV10505.dll.0.dr Static PE information: section name: .jedata
Source: XINV10505.dll.0.dr Static PE information: section name: .config
Source: XJCE10505.dll.0.dr Static PE information: section name: .jidata
Source: XJCE10505.dll.0.dr Static PE information: section name: .jedata
Source: XJCE10505.dll.0.dr Static PE information: section name: .config
Source: xjitb_j10505.dll.0.dr Static PE information: section name: .jidata
Source: xjitb_j10505.dll.0.dr Static PE information: section name: .jedata
Source: xjitb_j10505.dll.0.dr Static PE information: section name: .config
Source: XKRN10505.dll.0.dr Static PE information: section name: .jidata
Source: XKRN10505.dll.0.dr Static PE information: section name: .jedata
Source: XKRN10505.dll.0.dr Static PE information: section name: .config
Source: XMIA10505.dll.0.dr Static PE information: section name: .jidata
Source: XMIA10505.dll.0.dr Static PE information: section name: .jedata
Source: XMIA10505.dll.0.dr Static PE information: section name: .config
Source: XMIS10505.dll.0.dr Static PE information: section name: .jidata
Source: XMIS10505.dll.0.dr Static PE information: section name: .jedata
Source: XMIS10505.dll.0.dr Static PE information: section name: .config
Source: XMNG10505.dll.0.dr Static PE information: section name: .jidata
Source: XMNG10505.dll.0.dr Static PE information: section name: .jedata
Source: XMNG10505.dll.0.dr Static PE information: section name: .config
Source: XMSC10505.dll.0.dr Static PE information: section name: .jidata
Source: XMSC10505.dll.0.dr Static PE information: section name: .jedata
Source: XMSC10505.dll.0.dr Static PE information: section name: .config
Source: XPKC10505.dll.0.dr Static PE information: section name: .jidata
Source: XPKC10505.dll.0.dr Static PE information: section name: .jedata
Source: XPKC10505.dll.0.dr Static PE information: section name: .config
Source: XRMI10505.dll.0.dr Static PE information: section name: .jidata
Source: XRMI10505.dll.0.dr Static PE information: section name: .jedata
Source: XRMI10505.dll.0.dr Static PE information: section name: .config
Source: XSCR10505.dll.0.dr Static PE information: section name: .jidata
Source: XSCR10505.dll.0.dr Static PE information: section name: .jedata
Source: XSCR10505.dll.0.dr Static PE information: section name: .config
Source: XSEC10505.dll.0.dr Static PE information: section name: .jidata
Source: XSEC10505.dll.0.dr Static PE information: section name: .jedata
Source: XSEC10505.dll.0.dr Static PE information: section name: .config
Source: XSND10505.dll.0.dr Static PE information: section name: .jidata
Source: XSND10505.dll.0.dr Static PE information: section name: .jedata
Source: XSND10505.dll.0.dr Static PE information: section name: .config
Source: XSQL10505.dll.0.dr Static PE information: section name: .jidata
Source: XSQL10505.dll.0.dr Static PE information: section name: .jedata
Source: XSQL10505.dll.0.dr Static PE information: section name: .config
Source: XSSE10505.dll.0.dr Static PE information: section name: .jidata
Source: XSSE10505.dll.0.dr Static PE information: section name: .jedata
Source: XSSE10505.dll.0.dr Static PE information: section name: .config
Source: XSWN10505.dll.0.dr Static PE information: section name: .jidata
Source: XSWN10505.dll.0.dr Static PE information: section name: .jedata
Source: XSWN10505.dll.0.dr Static PE information: section name: .config
Source: XXML10505.dll.0.dr Static PE information: section name: .jidata
Source: XXML10505.dll.0.dr Static PE information: section name: .jedata
Source: XXML10505.dll.0.dr Static PE information: section name: .config
Source: XXWS10505.dll.0.dr Static PE information: section name: .jidata
Source: XXWS10505.dll.0.dr Static PE information: section name: .jedata
Source: XXWS10505.dll.0.dr Static PE information: section name: .config
Source: XXXL10505.dll.0.dr Static PE information: section name: .jidata
Source: XXXL10505.dll.0.dr Static PE information: section name: .jedata
Source: XXXL10505.dll.0.dr Static PE information: section name: .config
Source: HamSphere_4.010a.exe.0.dr Static PE information: section name: .jidata
Source: HamSphere_4.010a.exe.0.dr Static PE information: section name: .jedata
Source: HamSphere_4.010a.exe.0.dr Static PE information: section name: .config
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_3_16639070 push E003CADBh; retf 4_3_16639075
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_3_16635650 pushad ; ret 4_3_16635651
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_3_1663925F push cs; retf 4_3_16639262
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_3_16638FFF push cs; retf 4_3_16639002
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_3_166391D0 push E003CADBh; retf 4_3_166391D5
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_3_16639487 push cs; retf 4_3_1663948A
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_0040D150 push eax; mov dword ptr [esp], 00000000h 4_2_0040D153
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_004A3510 push eax; retf 4_2_004A3511
Source: msvcr100.dll.0.dr Static PE information: section name: .text entropy: 6.9169969425576285
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\JdbcOdbc.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSND10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XPKC10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\JAWTAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\net.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XEND10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSWN10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\Users\user\AppData\Local\Temp\InstTemp0\userinstall.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\zip.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\jsoundds.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XMIA10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSSE10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\t2k.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XMSC10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\Users\user\AppData\Local\Temp\xnsE6A3.tmp Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XMIS10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XXXL10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\jsound.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\JavaAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\unpack200.exe Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSCR10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\sunec.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\xjitb_j10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\msvcr100.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\WindowsAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\dcpr.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XJCE10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\j2pcsc.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\java.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\fontmanager.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSQL10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\Uninstall.exe Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\kcms.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\jawt.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\awt.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XINV10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XXML10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\cleanup.exe Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XKRN10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XIMG10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\w2k_lsa_auth.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\unpack.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XAWT10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\mlib_image.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XXWS10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\jetvm\jvm.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSEC10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\sunmscapi.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XCRB10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\nio.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XRMI10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XMNG10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\jaas_nt.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\j2pkcs11.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\rt\bin\jpeg.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe File created: C:\HamSphere\HamSphere_4.010a\install.log Jump to behavior
Source: C:\Users\user\Desktop\file.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HamSphere Jump to behavior
Source: C:\Users\user\Desktop\file.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HamSphere\HamSphere_4.010a Jump to behavior
Source: C:\Users\user\Desktop\file.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HamSphere\HamSphere_4.010a\HamSphere_4.010a.lnk Jump to behavior
Source: C:\Users\user\Desktop\file.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HamSphere\HamSphere_4.010a\Uninstall.lnk Jump to behavior
Source: C:\Users\user\Desktop\file.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\JdbcOdbc.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSND10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XPKC10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\JAWTAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\net.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XEND10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSWN10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\InstTemp0\userinstall.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XMIA10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\jsoundds.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\zip.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSSE10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\t2k.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XMSC10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\xnsE6A3.tmp Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XMIS10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XXXL10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\jsound.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\JavaAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\unpack200.exe Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSCR10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\sunec.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\xjitb_j10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\WindowsAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\msvcr100.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\dcpr.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XJCE10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\java.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\j2pcsc.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\fontmanager.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSQL10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\Uninstall.exe Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\kcms.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\jawt.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\awt.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XINV10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XXML10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\cleanup.exe Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XKRN10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XIMG10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\w2k_lsa_auth.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XAWT10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\unpack.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\mlib_image.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XXWS10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\jetvm\jvm.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XSEC10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\sunmscapi.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XCRB10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XRMI10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\nio.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\jetrt\XMNG10505.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\jaas_nt.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\j2pkcs11.dll Jump to dropped file
Source: C:\Users\user\Desktop\file.exe Dropped PE file which has not been started: C:\HamSphere\HamSphere_4.010a\rt\bin\jpeg.dll Jump to dropped file
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe API coverage: 5.1 %
Source: C:\Users\user\Desktop\file.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\file.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_00410110 GetModuleHandleA,FindFirstFileA,FindClose,FindFirstFileA,FindClose,LoadLibraryA,GetProcAddress,GetProcAddress, 4_2_00410110
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_0040F460 FindFirstFileA,FindClose, 4_2_0040F460
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_0040D7F0 FindFirstFileA,GetProcessHeap,HeapAlloc,FindNextFileA,FindClose, 4_2_0040D7F0
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_02396110 EntryPoint,DisableThreadLibraryCalls,GetModuleHandleA,FindFirstFileA,FindClose,FindFirstFileA,FindClose,LoadLibraryA,GetProcAddress,GetProcAddress, 4_2_02396110
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_02396710 FindFirstFileA,FindClose, 4_2_02396710
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Code function: 4_2_071B1740 FindFirstFileA,FindClose, 4_2_071B1740
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Hypervisor Logical ProcessorcalYq
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V bsipfxwncoqassp Bus Pipes'Pq
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Dynamic Memory Integration Service
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Virtual Machine Bus Pipesl[
Source: HamSphere_4.010a.exe, 00000004.00000003.1697516319.0000000000664000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1698015723.0000000000664000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1697909015.0000000000664000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1699125500.000000000065E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: eWorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DHyper-V Virtual Machine Bus Pipes
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V VM Vid Partitionlls
Source: HamSphere_4.010a.exe, 00000004.00000003.1697765672.0000000000664000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: c@.iWorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global
Source: HamSphere_4.010a.exe, 00000004.00000003.1699145652.0000000000676000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: unter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshot4890HWP Request MSR Context Switches/sec4892Guest Run Time4894Idle Time4896% Total Run Time4898% Hypervisor Run Time4900% Guest Run Time4902% Idle Time4904Total Interrupts/sec4788Hyper-V Hypervisor4790Logical Processors4792Partitions4794Total Pages4796Virtual Processors4798Monitored Notifications4800Modern Standby Entries4802Platform Idle Transitions4804HypervisorStartupCost4906Hyper-V Hypervisor Root Partition4908Virtual Processors4910Virtual TLB Pages4912Address Spaces4914Deposited Pages4916GPA Pages4918GPA Space Modifications/sec4920Virtual TLB Flush Entires/sec4922Recommended Virtual TLB Size49244K GPA pages49262M GPA pages49281G GPA pages4930512G GPA pages49324K device pages49342M device pages49361G device pages4938512G device pages4940Attached Devices4942Device Interrupt Mappings4944I/O TLB Flushes/sec4946I/O TLB Flush Cost4948Device Interrupt Errors4950Device DMA Errors4952Device Interrupt Throttle Events4954Skipped Timer Ticks4956Partition Id4958Nested TLB Size4960Recommended Nested TLB Size4962Nested TLB Free List Size4964Nested TLB Trimmed Pages/sec4966Pages Shattered/sec4968Pages Recombined/sec4970I/O TLB Flushes Base4972Hyper-V Hypervisor Root Virtual Processor4974Total Run Time4976Hypervisor Run Time4978Remote Node Run Time4980Normalized Run Time4982Ideal Cpu4984Hypercalls/sec4986Hypercalls Cost4988Page Invalidations/sec4990Page Invalidations Cost4992Control Register Accesses/sec4994Control Register Accesses Cost4996IO Instructions/sec4998IO Instructions Cost5000HLT Instructions/sec5002HLT Instructions Cost5004MWAIT Instructions/sec5006MWAIT Instructions Cost5008CPUID Instructions/sec5010CPUID Instructions Cost5012MSR Accesses/sec5014MSR Accesses Cost5016Other Intercepts/sec5018Other Intercepts Cost5020External Interrupts/sec5022External Interrupts Cost5024Pending Interrupts/sec5026Pending Interrupts Cost5028Emulated Instructions/sec5030Emulated Instructions Cost
Source: HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: com/sun/corba/se/impl/util/SUNVMCID.classPK
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Virtual Machine Bus Pipes
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Hypervisor Root PartitionL
Source: HamSphere_4.010a.exe, 00000004.00000003.1707733674.0000000004816000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: java/lang/VirtualMachineError.classvcf
Source: HamSphere_4.010a.exe, 00000004.00000003.1699718638.0000000000650000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1699218548.0000000000650000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1699745580.0000000000650000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0YfPQgWorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor L
Source: HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: osuE#java/lang/VirtualMachineError.classPK
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 2Hyper-V VM Vid PartitionQ
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VHyper-V Dynamic Memory Integration Servicell
Source: HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: Unable to create VirtualMachineError instance: it is abstract
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Hypervisor Root Virtual Processork
Source: HamSphere_4.010a.exe, 00000004.00000003.1705691642.0000000000641000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: h Entires/sec4922Recommended Virtual TLB Size49244K GPA pages49262M GPA pages49281G GPA pages4930512G GPA pages49324K device pages49342M device pages49361G device pages4938512G device pages4940Attached Devices4942Device Interrupt Mappings4944I/O TLB Flushes/sec4946I/O TLB Flush Cost4948Device Interrupt Errors4950Device DMA Errors4952Device Interrupt Throttle Events4954Skipped Timer Ticks4956Partition Id4958Nested TLB Size4960Recommended Nested TLB Size4962Nested TLB Free List Size4964Nested TLB Trimmed Pages/sec4966Pages Shattered/sec4968Pages Recombined/sec4970I/O TLB Flushes Base4972Hyper-V Hypervisor Root Virtual Processor4974Total Run Time4976Hypervisor Run Time4978Remote Node Run Time4980Normalized Run Time4982Ideal Cpu4984Hypercalls/sec4986Hypercalls Cost4988Page Invalidations/sec4990Page Invalidations Cost4992Control Register Accesses/sec4994Control Register Accesses Cost4996IO Instructions/sec4998IO Instructions Cost5000HLT Instructions/sec5002HLT Instructions Cost5004MWAIT Instructions/sec5006MWAIT Instructions Cost5008CPUID Instructions/sec5010CPUID Instructions Cost5012MSR Accesses/sec5014MSR Accesses Cost5016Other Intercepts/sec5018Other Intercepts Cost5020External Interrupts/sec5022External Interrupts Cost5024Pending Interrupts/sec5026Pending Interrupts Cost5028Emulated Instructions/sec5030Emulated Instructions Cost
Source: HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: osuE)com/sun/corba/se/impl/util/SUNVMCID.classPK
Source: HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: 'com/excelsior/jet/runtime/os/OSTime.javaQueryPerformanceCounter failedAverage VCF size: %zu bytesVCF Memory usage: total allocated %zu Mb, peak used %zu bytesVCF Generation time: total %d ms, average %d msNumber of VCF generated: %dCreateEvent() failedcom/excelsior/jet/runtime/os/Event.javaSetEvent() failedService initialization is failed to complete timelyNot enough memory for JVM initializationUnable to create ThreadDeath instance with message: no appropriate constructorUnknown exception code %dUnable to create VirtualMachineError instance: it is abstractcom/excelsior/jet/runtime/excepts/StandardExceptions.javaAJ fatal error: aj intrinsic com/excelsior/jet/runtime/excepts/StandardExceptions.__aj__callNewStandardException__Lcom_excelsior_aj_util_ManagedExecEnv_2Lcom_excelsior_jet_runtime_excepts_ExceptionCode_2Lcom_excelsior_aj_util_BString_2(ISI)Ljava/lang/Throwable; calledUnable to handle stack overflow at %p: unexpected instruction at %pUnable to handle stack overflow at %p: unexpected sub instruction at %pUnable to handle stack overflow at %p: unexpected add instruction at %pUnable to handle stack overflow at %p: unexpected mov instruction at %pUnable to handle stack overflow: too many instructions in the prologueUnable to handle stack overflow at %p: instruction bounds violatedUnexpected instructioncom/excelsior/jet/runtime/excepts/PrologueInterpreter.javaAJ fatal error: aj intrinsic com/excelsior/jet/runtime/excepts/o.value(I)I calledAJ fatal error: aj intrinsic com/excelsior/jet/runtime/excepts/o.__aj__invoke__Ljava_lang_Object_2I(ILjava/lang/Object;I)V calledAJ fatal error: aj intrinsic com/excelsior/jet/runtime/excepts/o.__aj__constr__Lcom_excelsior_aj_lang_CodeAddr_2(I)I calledAJ fatal error: aj intrinsic com/excelsior/jet/runtime/excepts/n.value(I)I calledAJ fatal error: aj intrinsic com/excelsior/jet/runtime/excepts/n.__aj__invoke__Ljava_lang_Object_2(ILjava/lang/Object;)V calledAJ fatal error: aj intrinsic com/excelsior/jet/runtime/excepts/n.__aj__constr__Lcom_excelsior_aj_lang_CodeAddr_2(I)I called
Source: HamSphere_4.010a.exe, 00000004.00000003.1707733674.0000000004816000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: c/java/lang/VirtualMachineError.classvcf
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Hypervisor Root PartitionWq
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VHyper-V Dynamic Memory Integration Servicellmq
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V bsipfxwncoqassp Bus
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Hypervisor Root Virtual Processor
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: THyper-V Hypervisor Root Virtual Processor
Source: HamSphere_4.010a.exe, 00000004.00000003.1705467810.0000000000640000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: cWorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864A
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DHyper-V Hypervisor Root Partition6
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: JHyper-V Hypervisor Logical Processorx
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: THyper-V Hypervisor Root Virtual Processor
Source: HamSphere_4.010a.exe, 00000004.00000002.2648927578.000000001327E000.00000008.00000001.01000000.0000000A.sdmp Binary or memory string: javax.management.relationsarpsborgreturn types do not match[negative prefix=CompositeType for Base GarbageCollectionNotificationInfoUTF_16LEMD2/RSAThe operation with name fillNewTypedArrayriodejaneiroprovided.null.namexn--hbmer-xqaKANGXIRADICALSKeySpec must be ECPrivateKeySpec or PKCS8EncodedKeySpec for EC private keysgetCallSiteTargetConnect timed outValue of jmx.remote.protocol.provider.pkgs parameter is not a String: custom writeObject data (class " (cast)Address inside [...] must be numeric IPv6 addressKey too long: X509CRLSelector.match: nextUpdate null is negativeUnimplemented: Resolver.findMethod(ClassFile)CompositeType for Base GcInfoNo Principal(s) specified __aj__winServiceInitialize__Lcom_excelsior_api_windows_types_DWORD_2Lcom_excelsior_aj_lang_Array_2invalid.null.Subject.provided__aj__GetByteArrayRegion__Lcom_excelsior_jet_runtime_jni_defs_JNIEnv_2Lcom_excelsior_jet_runtime_jni_defs_jbyteArray_2IILcom_excelsior_aj_lang_ByteArray_2timeout can't be negativeConstructor expectedClassbalsan>>> Credentials acquireServiceCreds: no realms list does not implement window can't be nullTemporary jar for classpath entry %s was not opened.800000000000000000000000000000000000000000000000000000000000000000000000100000000000000001\\\\controlNull host name: Unknown exception code %d[propertyName=Loaded from native configDuplicate name: Invalid encoding of URI exists but not with Unable to create VirtualMachineError instance: it is abstractremoteAddressreceived header line: "com.intellij.ide.plugins.PluginManagerFYL2XP1http.keepAlivecom.excelsior.jet.runtime.classload.nativelibs.NativeMethodsLinkingjava/lang/NoSuchMethodErrorOLD_PERSIANxn--rde-ulaCannot modify this registryMOVSXDwatchandclock5EEEFCA380D02919DC2C6558BB6D8A5DCloneNotSupportedException while cloning NameConstraintsException. This should never happen.__aj__CallFloatMethod__Lcom_excelsior_jet_runtime_jni_defs_JNIEnv_2Lcom_excelsior_jet_runtime_jni_defs_jobject_2Lcom_excelsior_jet_runtime_jni_defs_jmethodID_2_3Ljava_lang_Object_2Unsafe.defineAnonymousClass() does not support constant pool patchesen-GB-x-oedSHA224withECDSAagent.err.invalid.option, port: Illegal embedded sign characterxn--dyry-iraALPHABETICPRESENTATIONFORMS\\\"xn--hobl-iraArgument loabattromsohabmerJR_ThrowNegativeArraySizeExceptionJR_ThrowArrayStoreExceptiontrustjava.naming.corba.orbfilesxn--rland-uua
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: JHyper-V Hypervisor Logical Processor
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V VM Vid PartitionC[
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: sWDHyper-V Hypervisor Root Partition
Source: HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: com/sun/corba/se/impl/util/SUNVMCID.classvcf
Source: HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: org/omg/CORBA/OMGVMCID.classPK
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: &Hyper-V Hypervisor
Source: HamSphere_4.010a.exe, 00000004.00000003.1705467810.0000000000640000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Counter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshot4890HWP Request MSR Context Switches/sec4892Guest Run Time4894Idle Time4896% Total Run Time4898% Hypervisor Run Time4900% Guest Run Time4902% Idle Time4904Total Interrupts/sec4788Hyper-V Hypervisor4790Logical Processors4792Partitions4794Total Pages4796Virtual Processors4798Monitored Notifications4800Modern Standby Entries4802Platform Idle Transitions4804HypervisorStartupCost4906Hyper-V Hypervisor Root Partition4908Virtual Processors4910Virtual TLB Pages4912Address Spaces4914Deposited Pages4916GPA Pages4918GPA Space Modifications/sec4920Virtual TLB Flush Entires/sec4922Recommended Virtual TLB Size49244K GPA pages49262M GPA pages49281G GPA pages4930512G GPA pages49324K device pages49342M device pages49361G device pages4938512G device pages4940Attached Devices4942Device Interrupt Mappings4944I/O TLB Flushes/sec4946I/O TLB Flush Cost4948Device Interrupt Errors4950Device DMA Errors4952Device Interrupt Throttle Events4954Skipped Timer Ticks4956Partition Id4958Nested TLB Size4960Recommended Nested TLB Size4962Nested TLB Free List Size4964Nested TLB Trimmed Pages/sec4966Pages Shattered/sec4968Pages Recombined/sec4970I/O TLB Flushes Base4972Hyper-V Hypervisor Root Virtual Processor4974Total Run Time4976Hypervisor Run Time4978Remote Node Run Time4980Normalized Run Time4982Ideal Cpu4984Hypercalls/sec4986Hypercalls Cost4988Page Invalidations/sec4990Page Invalidations Cost4992Control Register Accesses/sec4994Control Register Accesses Cost4996IO Instructions/sec4998IO Instructions Cost5000HLT Instructions/sec5002HLT Instructions Cost5004MWAIT Instructions/sec5006MWAIT Instructions Cost5008CPUID Instructions/sec5010CPUID Instructions Cost5012MSR A
Source: HamSphere_4.010a.exe, 00000004.00000003.1699550229.0000000000650000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1699342799.0000000000650000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: WorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor L
Source: HamSphere_4.010a.exe, 00000004.00000002.2649473344.00000000133F9000.00000004.00000001.01000000.0000000A.sdmp Binary or memory string: java.lang.VirtualMachineError
Source: HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: java/lang/VirtualMachineError.classPK
Source: HamSphere_4.010a.exe, 00000004.00000003.1698630720.0000000000696000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 4010WEVT RPC calls/sec4012Events/sec4014ELF RPC calls/sec4016Active subscriptions4018Event filter operations/sec9568BranchCache9570Retrieval: Bytes from server9572Retrieval: Bytes from cache9574Retrieval: Bytes served9576Discovery: Weighted average discovery time9578SMB: Bytes from cache9580SMB: Bytes from server9582BITS: Bytes from cache9584BITS: Bytes from server9586WININET: Bytes from cache9588WININET: Bytes from server9590WINHTTP: Bytes from cache9592WINHTTP: Bytes from server9594OTHER: Bytes from cache9596OTHER: Bytes from server9598Discovery: Attempted discoveries9600Local Cache: Cache complete file segments9602Local Cache: Cache partial file segments9604Hosted Cache: Client file segment offers made9606Retrieval: Average branch rate9608Discovery: Successful discoveries9610Hosted Cache: Segment offers queue size9612Publication Cache: Published contents9614Local Cache: Average access time3432WSMan Quota Statistics3434Total Requests/Second3436User Quota Violations/Second3438System Quota Violations/Second3440Active Shells3442Active Operations3444Active Users3446Process ID1914Hyper-V VM Vid Partition1916Physical Pages Allocated1918Preferred NUMA Node Index1920Remote Physical Pages1922ClientHandles1924CompressPackTimeInUs1926CompressUnpackTimeInUs1928CompressPackInputSizeInBytes1930CompressUnpackInputSizeInBytes1932CompressPackOutputSizeInBytes1934CompressUnpackOutputSizeInBytes1936CompressUnpackUncompressedInputSizeInBytes1938CompressPackDiscardedSizeInBytes1940CompressWorkspaceSizeInBytes1942CompressScratchPoolSizeInBytes1944CryptPackTimeInUs1946CryptUnpackTimeInUs1948CryptPackInputSizeInBytes1950CryptUnpackInputSizeInBytes1952CryptPackOutputSizeInBytes1954CryptUnpackOutputSizeInBytes1956CryptScratchPoolSizeInBytes}
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: &Hyper-V Hypervisor
Source: HamSphere_4.010a.exe, 00000004.00000003.1700775753.000000000066D000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: eWorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Co
Source: HamSphere_4.010a.exe, 00000004.00000002.2639209035.00000000032C7000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: HamSphere_4.010a.exe, 00000004.00000003.1699322985.0000000000650000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1699502548.0000000000650000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: dWorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor L
Source: HamSphere_4.010a.exe, 00000004.00000003.1697338681.0000000000658000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: peWorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global
Source: HamSphere_4.010a.exe, 00000004.00000003.1705428574.0000000000646000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ctual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Counter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshot4890HWP Request MSR Context Switches/sec4892Guest Run Time4894Idle Time4896% Total Run Time4898% Hypervisor Run Time4900% Guest Run Time4902% Idle Time4904Total Interrupts/sec4788Hyper-V Hypervisor4790Logical Processors4792Partitions4794Total Pages4796Virtual Processors4798Monitored Notifications4800Modern Standby Entries4802Platform Idle Transitions4804HypervisorStartupCost4906Hyper-V Hypervisor Root Partition4908Virtual Processors4910Virtual TLB Pages4912Address Spaces4914Deposited Pages4916GPA Pages4918GPA Space Modifications/sec4920Virtual TLB Flush Entires/sec4922Recommended Virtual TLB Size49244K GPA pages49262M GPA pages49281G GPA pages4930512G GPA pages49324K device pages49342M device pages49361G device pages4938512G device pages4940Attached Devices4942Device Interrupt Mappings4944I/O TLB Flushes/sec4946I/O TLB Flush Cost4948Device Interrupt Errors4950Device DMA Errors4952Device Interrupt Throttle Events4954Skipped Timer Ticks4956Partition Id4958Nested TLB Size4960Recommended Nested TLB Size4962Nested TLB Free List Size4964Nested TLB Trimmed Pages/sec4966Pages Shattered/sec4968Pages Recombined/sec4970I/O TLB Flushes Base4972Hyper-V Hypervisor Root Virtual Processor4974Total Run Time4976Hypervisor Run Time4978Remote Node Run Time4980Normalized Run Time4982Ideal Cpu4984Hypercalls/sec4986Hypercalls Cost4988Page Invalidations/sec4990Page Invalidations Cost4992Control Register Accesses/sec4994Control Register Accesses Cost4996IO Instructions/sec4998IO Instructions Cost5000HLT Instructions/sec5002HLT Instructions Cost5004MWAIT Instructions/sec5006MWAIT Instructions Cost5008CPUID Instructions/sec5010CPUID Instructions Cost5012MSR Accesses/sec5014MSR Accesses Cost5016Other Intercepts/sec5018Other Intercepts Cost5020External Interrupts/sec5022External Interrupts Cost5024Pending Interrupts/sec5026Pending Interrupts Cost5028Emulated Instructions/sec5030Emulated Instructions Cost5032Debug Register Accesses/sec5034Debug Register Accesses Cost5036Page Fault Intercepts/sec5038Page Fault Intercepts Cost5040NMI Interrupts/sec5042NMI Interrupts Cost5044Guest Page Table Maps/sec5046Large Page TLB Fills/sec5048Small Page TLB Fills/sec5050Reflected Guest Page Faults/sec5052APIC MMIO Accesses/sec5054IO Intercept Messages/sec5056Memory Intercept Messages/sec5058APIC EOI Accesses/sec5060Other Messages/sec5062Page Table Allocations/sec5064Logical Processor Migrations/sec5066Address Space Evictions/sec5068Address Space Switches/sec5070Address Domain Flushes/sec5072Address Space Flushes/sec5074Global GVA Range Flushes/sec5076Loca
Source: HamSphere_4.010a.exe, 00000004.00000003.1698837896.000000000066D000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1699100195.0000000000666000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1699002525.0000000000650000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: eWorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Counter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshot4890HWP Request MSR Context Switches/sec4892Guest Run Time4894Idle Time4896% Total Run Time4898% Hypervisor Run Time4900% Guest Run Time4902% Idle Time4904Total Interrupts/sec4788Hyper-V Hypervisor4790Logical Processors4792Partitions4794Total Pages4796Virtual Processors4798Monitored Notifications4800Modern Standby Entries4802Platform Idle Transitions4804HypervisorStartupCost4906Hyper-V Hypervisor Root Partition4908Virtual Processors4910Virtual TLB Pages4912Address Spaces4914Deposited Pages4916GPA Pages4918GPA Space Modifications/sec4920Virtual TLB Flush Entires/sec4922Recommended Virtual TLB Size49244K GPA pages49262M GPA pages49281G GPA pages4930512G GPA pages49324K device pages49342M device pages49361G device pages4938512G device pages4940Attached Devices4942Device Interrupt Mappings4944I/O TLB Flushes/sec4946I/O TLB Flush Cost4948Device Interrupt Errors4950Device DMA Errors4952Device Interrupt Throttle Events4954Skipped Timer Ticks4956Partition Id4958Nested TLB Size4960Recommended Nested TLB Size4962Nested TLB Free List Size4964Nested TLB Trimmed Pages/sec4966Pages Shattered/sec4968Pages Recombined/sec4970I/O TLB
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: AlDHyper-V Virtual Machine Bus Pipes
Source: HamSphere_4.010a.exe, 00000004.00000003.1699201195.0000000000650000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: dPQgWorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor L
Source: HamSphere_4.010a.exe, 00000004.00000002.2651157458.000000001373B000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: org/omg/CORBA/OMGVMCID.classvcf
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Dynamic Memory Integration Service.Rq
Source: HamSphere_4.010a.exe, 00000004.00000003.1697516319.0000000000664000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1698015723.0000000000664000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1697909015.0000000000664000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1698221198.0000000000664000.00000004.00000020.00020000.00000000.sdmp, HamSphere_4.010a.exe, 00000004.00000003.1697765672.0000000000664000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: tions failed due to ineligible container3190Compactions failed due to max fragmentation3192Container Move Retry Count3194Container moves failed due to ineligible container3196Compaction Failure Count3198Container Move Failure Count3200Dirty metadata pages3202Dirty table list entries3204Delete Queue entries9698Storage Management WSP Spaces Runtime9700Runtime Count 4ms9702Runtime Count 16ms9704Runtime Count 64ms9706Runtime Count 256ms9708Runtime Count 1s9710Runtime Count 4s9712Runtime Count 16s9714Runtime Count 1min9716Runtime Count Infinite3094Hyper-V Virtual Machine Bus Pipes3096Reads/sec3098Writes/sec3100Bytes Read/sec3102Bytes Written/sec9616SMB Direct Connection9618Stalls (Send Credit)/sec9620Stalls (Send Queue)/sec9622Stalls (RDMA Registrations)/sec9624Sends/sec9626Remote Invalidations/sec9628Memory Regions9630Bytes Received/sec9632Bytes Sent/sec9634Bytes RDMA Read/sec9636Bytes RDMA Written/sec9638Stalls (RDMA Read)/sec9640Receives/sec9642RDMA Registrations/sec9644SCQ Notification Events/sec9646RCQ Notification Events/sec9648Spurious RCQ Notification Events9650Spurious SCQ Notification Events9504Offline Files9506Bytes Received9508Bytes Transmitted9510Bytes Transmitted/sec9514Bytes Received/sec9518Client Side Caching9520SMB BranchCache Bytes Requested9522SMB BranchCache Bytes Received9524SMB BranchCache Bytes Published9526SMB BranchCache Bytes Requested From Server9528SMB BranchCache Hashes Requested9530SMB BranchCache Hashes Received9532SMB BranchCache Hash Bytes Received9534Prefetch Operations Queued9536Prefetch Bytes Read From Cache9538Prefetch Bytes Read From Server9540Application Bytes Read From Cache9542Application Bytes Read From Server9544Application Bytes Read From Server (Not Cached)3260Teredo Relay3262In - Teredo Relay Total Packets: Success + Error
Source: HamSphere_4.010a.exe, 00000004.00000002.2649473344.00000000133F9000.00000004.00000001.01000000.0000000A.sdmp Binary or memory string: +Sjava.lang.VirtualMachineError
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Hypervisor Logical Processor
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: X2Hyper-V VM Vid Partition4RE
Source: HamSphere_4.010a.exe, 00000004.00000003.1705691642.0000000000645000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: iWorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864A
Source: HamSphere_4.010a.exe, 00000004.00000002.2636523787.00000000005BD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V Hypervisor
Source: C:\Users\user\Desktop\file.exe API call chain: ExitProcess graph end node
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\file.exe Code function: 0_2_00FC185E EntryPoint,lstrcmpA,lstrcmpA,lstrcmpA,CloseHandle,CloseHandle,CloseHandle,LoadLibraryA,GetProcAddress,FreeLibrary,FreeLibrary,ExitProcess, 0_2_00FC185E
Source: C:\Users\user\Desktop\file.exe Code function: 0_2_00FC1195 GetProcessHeap,RtlFreeHeap, 0_2_00FC1195
Source: C:\Users\user\Desktop\file.exe Process created: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe "C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe" Jump to behavior
Source: C:\Users\user\Desktop\file.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\file.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\HamSphere\HamSphere_4.010a\HamSphere_4.010a.exe Key value queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation DynamicDaylightTimeDisabled Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs