Source: papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://127.0.0.1:9263image: |
Source: vcredist_x64.exe.2.dr |
String found in binary or memory: http://appsyndication.org/2006/appsynapplicationc: |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://bourbon.io |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalG3CodeSigningECCSHA3842021CA1.crt0 |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG3.crt0B |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalG3CodeSigningECCSHA3842021CA1.crl0N |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG3.crl0 |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: pc-print-client.exe.2.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalG3CodeSigningECCSHA3842021CA1.crl0 |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: pc-print-client.exe, 00000012.00000002.2631688601.000000C000020000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://localhostus-genesisstaginggngkernel32.dllC: |
Source: pc-print-client.exe.2.dr |
String found in binary or memory: http://ocsp.digicert.com0 |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://ocsp.digicert.com0A |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://ocsp.digicert.com0C |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://ocsp.digicert.com0W |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://ocsp.digicert.com0X |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://www.bohemiancoding.com/sketch |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F3DA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000035EE000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: http://www.digicert.com/CPS0 |
Source: papercut-hive.exe, 00000000.00000003.2707442358.0000000001836000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702866559.00000000030B6000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://www.papercut.com/ |
Source: papercut-hive.exe, 00000000.00000003.2091285016.00000000034D0000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2096649458.0000000003F90000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://www.papercut.com/0http://www.papercut.com/0http://www.papercut.com/ |
Source: papercut-hive.tmp, 00000002.00000003.2702866559.00000000030B6000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://www.papercut.com/Yk |
Source: pc-print-client.exe, 00000012.00000002.2631688601.000000C000022000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://.papercusoftwarehttp://lus-genestesttstau-stagitemplate |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://127.0.0.1:9266idna: |
Source: papercut-hive.tmp, 00000002.00000003.2704291741.0000000001590000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/ |
Source: papercut-hive.tmp, 00000002.00000003.2704291741.0000000001590000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/YoS(& |
Source: papercut-hive.exe, 00000000.00000003.2091285016.00000000034D0000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2707442358.00000000017E3000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2704291741.00000000015A7000.00000004.00000020.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702866559.0000000003007000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702370361.0000000004230000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2096649458.0000000003F90000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2704291741.0000000001590000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/vs/17/release/vc_redist.x64.exe |
Source: papercut-hive.tmp, 00000002.00000002.2705901345.0000000001595000.00000004.00000020.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2704291741.0000000001590000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/vs/17/release/vc_redist.x64.exe4 |
Source: papercut-hive.tmp, 00000002.00000003.2698392651.0000000004015000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/vs/17/release/vc_redist.x64.exe== |
Source: papercut-hive.tmp, 00000002.00000002.2705901345.0000000001595000.00000004.00000020.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2704291741.0000000001590000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/vs/17/release/vc_redist.x64.exeH |
Source: papercut-hive.tmp, 00000002.00000003.2698392651.0000000004015000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/vs/17/release/vc_redist.x64.exet)) |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://au-staging.pmitc.papercut.softwareinsufficient |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://au.pmitc.papercut.comhttps://eu.pmitc.papercut.comhttps://uk.pmitc.papercut.cominteger |
Source: papercut-hive.tmp, 00000002.00000002.2706959213.0000000006650000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://cdn1.papercut.com/ |
Source: papercut-hive.tmp, 00000002.00000003.2704291741.00000000015C8000.00000004.00000020.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702370361.0000000004230000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2698392651.0000000004015000.00000004.00000020.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2096649458.0000000003F90000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://cdn1.papercut.com/files/open-source/ghost-trap/ghost-trap-installer-1.5.10.03.exe |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.googleapis.com |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.googleapis.com/css2?family=Barlow:ital |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/barlow/v12/7cHpv4kjgoGqM7E_DMs8.ttf) |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/barlow/v12/7cHqv4kjgoGqM7E30-8s51op.ttf) |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/barlow/v12/7cHqv4kjgoGqM7E3j-ws51op.ttf) |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/merriweather/v30/u-440qyriQwlOrhSvowK_l5-fCZJ.ttf) |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/merriweather/v30/u-4n0qyriQwlOrhSvowK_l52xwNZWMf_.ttf) |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/sourcecodepro/v22/HI_diYsKILxRpg3hIP6sJ7fM7PqPMcMnZFqUwX28DMyQtMlrSQ.ttf |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/sourcesanspro/v21/6xK1dSBYKcSV-LCoeQqfX1RYOo3qPZ7nsDc.ttf) |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/sourcesanspro/v21/6xK3dSBYKcSV-LCoeQqfX1RYOo3qOK7g.ttf) |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/sourcesanspro/v21/6xKwdSBYKcSV-LCoeQqfX1RYOo3qPZY4lCds18E.ttf) |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/sourcesanspro/v21/6xKydSBYKcSV-LCoeQqfX1RYOo3i54rwlxdr.ttf) |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.00000000044B5000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://fonts.gstatic.com/s/sourcesanspro/v21/6xKydSBYKcSV-LCoeQqfX1RYOo3i94_wlxdr.ttf) |
Source: papercut-hive.exe, 00000000.00000003.2091285016.00000000034D0000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2707442358.00000000017E3000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702866559.0000000003007000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702370361.000000000428D000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702866559.0000000002FEA000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2096649458.0000000003F90000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/PaperCutSoftware/GhostTrap |
Source: papercut-hive.tmp, 00000002.00000003.2702866559.0000000002FEA000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/PaperCutSoftware/GhostTrapn; |
Source: papercut-hive.exe, 00000000.00000003.2091285016.00000000034D0000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2707442358.00000000017E3000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702866559.0000000003007000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702370361.000000000423A000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2096649458.0000000003F90000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://installer-downloader-dot-pc-pmitc.appspot.com/public/installer-downloader/upload-installer-l |
Source: papercut-hive.exe |
String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: pc-print-client.exe, 00000012.00000002.2631688601.000000C0000FF000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2631688601.000000C0000CC000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://multiverse.papercut.com |
Source: pc-print-client.exe, 00000012.00000002.2631688601.000000C0000FF000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2631688601.000000C0000CC000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://multiverse.papercut.software |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://pc-pmitc.appspot.com//print-client/secure/printclient-gateway/org/%s/upload-support-logs/v1c |
Source: pc-print-client.exe, 00000012.00000002.2631688601.000000C000022000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://pmitc.papercut.com/ |
Source: papercut-hive.tmp, 00000002.00000003.2698494496.0000000004310000.00000004.00001000.00020000.00000000.sdmp, pc-print-client.exe, 00000012.00000002.2630254047.0000000000F85000.00000002.00000001.01000000.0000000A.sdmp, pc-print-client.exe.2.dr |
String found in binary or memory: https://protobuf.dev/reference/go/faq#namespace-conflictin |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F0DB000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000034D0000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000000.2094710725.0000000000B01000.00000020.00000001.01000000.00000004.sdmp |
String found in binary or memory: https://www.innosetup.com/ |
Source: papercut-hive.exe, 00000000.00000003.2091285016.00000000034D0000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2707442358.00000000017E3000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702866559.0000000003007000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702370361.000000000429C000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2096649458.0000000003F90000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://www.papercut.com/kb/PaperCutPocketHive/PrinterInstallerIssue#portconflict |
Source: papercut-hive.exe, 00000000.00000003.2091285016.00000000034D0000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2707442358.00000000017E3000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702866559.0000000003007000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702866559.0000000003064000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2096649458.0000000003F90000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://www.papercut.com/kb/PaperCutPocketHive/PrinterInstallerIssue#services |
Source: papercut-hive.exe, 00000000.00000003.2091285016.00000000034D0000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2707442358.00000000017E3000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702866559.0000000003007000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2702866559.0000000003064000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000003.2096649458.0000000003F90000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://www.papercut.com/kb/PaperCutPocketHive/PrinterInstallerIssue#win |
Source: papercut-hive.exe, 00000000.00000003.2093280982.000000007F0DB000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.exe, 00000000.00000003.2092843159.00000000034D0000.00000004.00001000.00020000.00000000.sdmp, papercut-hive.tmp, 00000002.00000000.2094710725.0000000000B01000.00000020.00000001.01000000.00000004.sdmp |
String found in binary or memory: https://www.remobjects.com/ps |
Source: unknown |
Process created: C:\Users\user\Desktop\papercut-hive.exe "C:\Users\user\Desktop\papercut-hive.exe" |
|
Source: C:\Users\user\Desktop\papercut-hive.exe |
Process created: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp "C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp" /SL5="$1047A,31229352,845824,C:\Users\user\Desktop\papercut-hive.exe" |
|
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" "C:\Windows\system32\cmd.exe" /S /C ""netstat" -anb > "C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\~execwithresult.txt"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\NETSTAT.EXE "netstat" -anb |
|
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C wmic /namespace:\\root\SecurityCenter2 path AntiVirusProduct get * /value > "C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\antivirus-info.log" 2>&1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wbem\WMIC.exe wmic /namespace:\\root\SecurityCenter2 path AntiVirusProduct get * /value |
|
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Windows\System32\taskkill.exe "taskkill.exe" /f /im "pc-print-client-service.exe" |
|
Source: C:\Windows\System32\taskkill.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Windows\System32\taskkill.exe "taskkill.exe" /f /im "pc-print-client.exe" |
|
Source: C:\Windows\System32\taskkill.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Windows\System32\net.exe "net.exe" start spooler |
|
Source: C:\Windows\System32\net.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\net.exe |
Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 start spooler |
|
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe "C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe" -installPrintQueue -printerId="PaperCut Printer" -printerName="PaperCut Printer" "-driverFilePath=C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\PC-Global-Print-Driver\PCGlobal.inf" -logFile="C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\queue_install.log" |
|
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe printui.dll,PrintUIEntry /ia /m "PaperCut Global PostScript - NTNS" /f C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\PC-Global-Print-Driver\PCGlobal.inf /u |
|
Source: unknown |
Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{4744f51b-c3b4-8c45-9965-84928136fda2}\pcglobal.inf" "9" "48fde5adf" "000000000000015C" "WinSta0\Default" "0000000000000144" "208" "c:\users\user\appdata\local\temp\is-b2r1d.tmp\client\pc-global-print-driver" |
|
Source: unknown |
Process created: C:\Windows\System32\PrintIsolationHost.exe C:\Windows\system32\PrintIsolationHost.exe -Embedding |
|
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe printui.dll,PrintUIEntry /y /if /b "PaperCut Printer" /x /n "PaperCut Printer" /m "PaperCut Global PostScript - NTNS" /r http://localhost:9265/printers/papercutpocket /u /q |
|
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe printui.dll,PrintUIEntry /q /y /n "PaperCut Printer" |
|
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe printui.dll,PrintUIEntry /q /Sr /n "PaperCut Printer" /a C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\printer-settings.bin p h i r g u d c 2 |
|
Source: C:\Users\user\Desktop\papercut-hive.exe |
Process created: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp "C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp" /SL5="$1047A,31229352,845824,C:\Users\user\Desktop\papercut-hive.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" "C:\Windows\system32\cmd.exe" /S /C ""netstat" -anb > "C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\~execwithresult.txt"" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C wmic /namespace:\\root\SecurityCenter2 path AntiVirusProduct get * /value > "C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\antivirus-info.log" 2>&1 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Windows\System32\taskkill.exe "taskkill.exe" /f /im "pc-print-client-service.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Windows\System32\taskkill.exe "taskkill.exe" /f /im "pc-print-client.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Windows\System32\net.exe "net.exe" start spooler |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process created: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe "C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe" -installPrintQueue -printerId="PaperCut Printer" -printerName="PaperCut Printer" "-driverFilePath=C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\PC-Global-Print-Driver\PCGlobal.inf" -logFile="C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\queue_install.log" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\NETSTAT.EXE "netstat" -anb |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wbem\WMIC.exe wmic /namespace:\\root\SecurityCenter2 path AntiVirusProduct get * /value |
Jump to behavior |
Source: C:\Windows\System32\net.exe |
Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 start spooler |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe printui.dll,PrintUIEntry /ia /m "PaperCut Global PostScript - NTNS" /f C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\PC-Global-Print-Driver\PCGlobal.inf /u |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe printui.dll,PrintUIEntry /y /if /b "PaperCut Printer" /x /n "PaperCut Printer" /m "PaperCut Global PostScript - NTNS" /r http://localhost:9265/printers/papercutpocket /u /q |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe printui.dll,PrintUIEntry /q /y /n "PaperCut Printer" |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe printui.dll,PrintUIEntry /q /Sr /n "PaperCut Printer" /a C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\printer-settings.bin p h i r g u d c 2 |
Jump to behavior |
Source: C:\Users\user\Desktop\papercut-hive.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\papercut-hive.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: wtsapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: msftedit.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: windows.globalization.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: bcp47mrm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: globinputhost.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: windows.ui.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: windowmanagementapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: inputhost.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: twinapi.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: twinapi.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Section loaded: explorerframe.dll |
Jump to behavior |
Source: C:\Windows\System32\NETSTAT.EXE |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\NETSTAT.EXE |
Section loaded: snmpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\NETSTAT.EXE |
Section loaded: inetmib1.dll |
Jump to behavior |
Source: C:\Windows\System32\NETSTAT.EXE |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: msxml6.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: vcruntime140.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: vcruntime140_1.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\net.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\net.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Windows\System32\net.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\net.exe |
Section loaded: samcli.dll |
Jump to behavior |
Source: C:\Windows\System32\net.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\net.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\net1.exe |
Section loaded: samcli.dll |
Jump to behavior |
Source: C:\Windows\System32\net1.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\net1.exe |
Section loaded: dsrole.dll |
Jump to behavior |
Source: C:\Windows\System32\net1.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\net1.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Windows\System32\net1.exe |
Section loaded: logoncli.dll |
Jump to behavior |
Source: C:\Windows\System32\net1.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Section loaded: devrtl.dll |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Section loaded: drvstore.dll |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Section loaded: cabinet.dll |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\PrintIsolationHost.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\PrintIsolationHost.exe |
Section loaded: printisolationproxy.dll |
Jump to behavior |
Source: C:\Windows\System32\PrintIsolationHost.exe |
Section loaded: spoolss.dll |
Jump to behavior |
Source: C:\Windows\System32\PrintIsolationHost.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\PrintIsolationHost.exe |
Section loaded: mscms.dll |
Jump to behavior |
Source: C:\Windows\System32\PrintIsolationHost.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\PrintIsolationHost.exe |
Section loaded: coloradapterclient.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\papercut-hive.exe |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-7B4BH.tmp\papercut-hive.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wbem\WMIC.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B2R1D.tmp\client\pc-print-client.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\drvinst.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\PrintIsolationHost.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |