Source: | Binary string: C:\b\w\d6337ac2abf63a4b\.repositories\DependencyInjection\src\Microsoft.Extensions.DependencyInjection.Abstractions\bin\Release\netstandard1.0\Microsoft.Extensions.DependencyInjection.Abstractions.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: mscorlib.pdb source: WER2F60.tmp.dmp.3.dr |
Source: | Binary string: D:\a\1\s\xpdBootstrapper\obj\Release\net472\xpdBootstrapper.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: E:\A\_work\708\s\corefx\bin\obj\AnyOS.AnyCPU.Release\System.Diagnostics.DiagnosticSource\net46\System.Diagnostics.DiagnosticSource.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: D:\a\1\s\Microsoft.Applications.Events\obj\Server\netstandard1.3\Microsoft.Applications.Events.Server.pdbSHA256 source: 5XpKRbh2k7.exe |
Source: | Binary string: mscorlib.ni.pdb source: WER2F60.tmp.dmp.3.dr |
Source: | Binary string: D:\a\1\s\Microsoft.Applications.Events\obj\Server\netstandard1.3\Microsoft.Applications.Events.Server.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: D:\a\1\s\OTelCS.Net461\Sources\OneCollector\obj\Release\Microsoft.Office.Telemetry.OneCollector.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: D:\a\1\s\EventFlags.Net45\Sources\obj\Release\Microsoft.Office.Telemetry.EventFlags.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: D:\a\1\s\EventFlags.Net45\Sources\obj\Release\Microsoft.Office.Telemetry.EventFlags.pdb|A source: 5XpKRbh2k7.exe |
Source: | Binary string: D:\a\1\s\OTelCS.Net461\Sources\TelemetryService\obj\Release\OTelCS.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: mscorlib.ni.pdbRSDS7^3l source: WER2F60.tmp.dmp.3.dr |
Source: | Binary string: C:\b\w\d6337ac2abf63a4b\.repositories\Logging\src\Microsoft.Extensions.Logging.Abstractions\bin\Release\netstandard1.1\Microsoft.Extensions.Logging.Abstractions.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: C:\b\w\d6337ac2abf63a4b\.repositories\Microsoft.Data.Sqlite\src\Microsoft.Data.Sqlite\bin\Release\netstandard1.3\Microsoft.Data.Sqlite.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: C:\b\w\d6337ac2abf63a4b\.repositories\Logging\src\Microsoft.Extensions.Logging\bin\Release\netstandard1.1\Microsoft.Extensions.Logging.pdb source: 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | String found in binary or memory: http://corppki/aia/MSIT%20CA%20Z1(2).crt0E |
Source: 5XpKRbh2k7.exe | String found in binary or memory: http://corppki/aia/msintcrca.crt0= |
Source: 5XpKRbh2k7.exe | String found in binary or memory: http://corppki/crl/MSIT%20CA%20Z1(2).crl |
Source: 5XpKRbh2k7.exe | String found in binary or memory: http://corppki/crl/msintcrca.crl |
Source: 5XpKRbh2k7.exe | String found in binary or memory: http://sqlite.org/rescode.html |
Source: Amcache.hve.3.dr | String found in binary or memory: http://upx.sf.net |
Source: 5XpKRbh2k7.exe | String found in binary or memory: http://www.asp.net/ |
Source: 5XpKRbh2k7.exe | String found in binary or memory: https://pipe.int.trafficmanager.net/OneCollector/1.0/ |
Source: 5XpKRbh2k7.exe | String found in binary or memory: https://support.office.com/oReplacing |
Source: 5XpKRbh2k7.exe, 00000000.00000000.1682954949.000001EE03462000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Applications.Events.Server.dllj% vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, 00000000.00000000.1682954949.000001EE03462000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Data.Sqlite.dll> vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, 00000000.00000000.1682954949.000001EE03462000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Extensions.DependencyInjection.Abstractions.dllT vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, 00000000.00000000.1682954949.000001EE03462000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Extensions.Logging.dllT vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, 00000000.00000000.1682954949.000001EE03462000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Extensions.Logging.Abstractions.dllT vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, 00000000.00000000.1682954949.000001EE03462000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Office.Telemetry.EventFlags.dlll& vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, 00000000.00000000.1682954949.000001EE03462000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Office.Telemetry.OneCollector.dllB vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, 00000000.00000000.1682954949.000001EE03462000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameOTelCS.dll. vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, 00000000.00000000.1682954949.000001EE03462000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameSystem.Diagnostics.DiagnosticSource.dllT vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, 00000000.00000000.1682954949.000001EE036E7000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenamexpdBootstrapper.exeX vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | Binary or memory string: OriginalFilenameMicrosoft.Applications.Events.Server.dllj% vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | Binary or memory string: OriginalFilenameMicrosoft.Data.Sqlite.dll> vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | Binary or memory string: OriginalFilenameMicrosoft.Extensions.DependencyInjection.Abstractions.dllT vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | Binary or memory string: OriginalFilenameMicrosoft.Extensions.Logging.dllT vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | Binary or memory string: OriginalFilenameMicrosoft.Extensions.Logging.Abstractions.dllT vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | Binary or memory string: OriginalFilenameMicrosoft.Office.Telemetry.EventFlags.dlll& vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | Binary or memory string: OriginalFilenameMicrosoft.Office.Telemetry.OneCollector.dllB vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | Binary or memory string: OriginalFilenameOTelCS.dll. vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | Binary or memory string: OriginalFilenameSystem.Diagnostics.DiagnosticSource.dllT vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe | Binary or memory string: OriginalFilenamexpdBootstrapper.exeX vs 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, IAppxBundleReader.cs | Suspicious method names: ..GetPayloadPackage |
Source: 5XpKRbh2k7.exe, IAppxBundleReader.cs | Suspicious method names: ..GetPayloadPackages |
Source: 5XpKRbh2k7.exe, IAppxPackageWriter.cs | Suspicious method names: ..AddPayloadFile |
Source: 5XpKRbh2k7.exe, IAppxPackageReader.cs | Suspicious method names: ..GetPayloadFile |
Source: 5XpKRbh2k7.exe, IAppxPackageReader.cs | Suspicious method names: ..GetPayloadFiles |
Source: 5XpKRbh2k7.exe, Program.cs | Suspicious method names: .Program.GetPayload |
Source: 5XpKRbh2k7.exe, Program.cs | Suspicious method names: .Program.InjectResources |
Source: 5XpKRbh2k7.exe, Program.cs | Suspicious method names: .Program.PayloadFromPackage |
Source: 5XpKRbh2k7.exe | String found in binary or memory: --help |
Source: 5XpKRbh2k7.exe | String found in binary or memory: --help |
Source: 5XpKRbh2k7.exe | String found in binary or memory: !/silent /installQRunning WebView2 Evergreen bootstrapper.[WebView2 Evergreen bootstrapper has been run.aError running WebView2 Evergreen bootstrapper: ' |
Source: 5XpKRbh2k7.exe | String found in binary or memory: Try `= --help' for more information. |
Source: 5XpKRbh2k7.exe | String found in binary or memory: Try `= --help' for more information. |
Source: 5XpKRbh2k7.exe | String found in binary or memory: install/Installs a packaged app?Installs a packaged application!p:|pkg:|package: |
Source: 5XpKRbh2k7.exe | String found in binary or memory: launch/Launches an application/pfn:|packageFamilyName:kPackage family name of the application to be launchedeCommand line to pass into the launched applicationlistYLists all versions of the app on this device |
Source: 5XpKRbh2k7.exe | String found in binary or memory: Input does not match expected format: [x-y]. Run xpdAgent.exe configure-buckets --help to see formatting instructions |
Source: 5XpKRbh2k7.exe | String found in binary or memory: Input does not match expected format: [x-y]. Run xpdAgent.exe configure-buckets --help to see formatting instructions |
Source: 5XpKRbh2k7.exe | String found in binary or memory: Unable to parse range. Run xpdAgent.exe configure-buckets --help to see formatting instructions |
Source: 5XpKRbh2k7.exe | String found in binary or memory: Unable to parse range. Run xpdAgent.exe configure-buckets --help to see formatting instructions |
Source: 5XpKRbh2k7.exe | String found in binary or memory: IChecking installation prerequisites.yAt least one installation prerequisite was not met, exiting.KCompleted installation prerequisites./Installation succeeded.EInstallation failed with exception |
Source: 5XpKRbh2k7.exe | String found in binary or memory: qFailed to add persistent data fields to an unusable sink/AddPersistentDataFields!Dropping event: %SendTelemetryEvent9Event name was null or empty |
Source: 5XpKRbh2k7.exe | String found in binary or memory: {"indirect":"false","quiet":"false","errorBaseUrl":"https://go.microsoft.com/fwlink/","errorParameters":"linkid=2238672","packageFamilyName":"Microsoft.OutlookForWindows_8wekyb3d8bbwe","applicationId":"Microsoft.OutlookforWindows","arm64":"https://res.cdn.office.net/nativehost/5mttl/installer/v2/1.2024.1018.100/Microsoft.OutlookForWindows_arm64.msix","x86":"https://res.cdn.office.net/nativehost/5mttl/installer/v2/1.2024.1018.100/Microsoft.OutlookForWindows_x86.msix","x64":"https://res.cdn.office.net/nativehost/5mttl/installer/v2/1.2024.1018.100/Microsoft.OutlookForWindows_x64.msix","CompanyName":"Microsoft Corporation","FileDescription":"Microsoft Outlook Installer","FileVersion":"1.2024.1018.100","LegalCopyright":"Copyright (C) Microsoft Corporation. All rights reserved.","ProductName":"Microsoft Outlook Installer","ProductVersion":"1.2024.1018.100","packageManifest":"C:\\a\\_work\\1\\b\\2\\_work\\1\\s\\build\\win-x64-release\\xpdPackLogs\\AppXManifest.xml","errorBackgroundColor":"#ffffff","errorTextColor":"#737474","enableStubMode":"true"}PA |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: | Binary string: C:\b\w\d6337ac2abf63a4b\.repositories\DependencyInjection\src\Microsoft.Extensions.DependencyInjection.Abstractions\bin\Release\netstandard1.0\Microsoft.Extensions.DependencyInjection.Abstractions.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: mscorlib.pdb source: WER2F60.tmp.dmp.3.dr |
Source: | Binary string: D:\a\1\s\xpdBootstrapper\obj\Release\net472\xpdBootstrapper.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: E:\A\_work\708\s\corefx\bin\obj\AnyOS.AnyCPU.Release\System.Diagnostics.DiagnosticSource\net46\System.Diagnostics.DiagnosticSource.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: D:\a\1\s\Microsoft.Applications.Events\obj\Server\netstandard1.3\Microsoft.Applications.Events.Server.pdbSHA256 source: 5XpKRbh2k7.exe |
Source: | Binary string: mscorlib.ni.pdb source: WER2F60.tmp.dmp.3.dr |
Source: | Binary string: D:\a\1\s\Microsoft.Applications.Events\obj\Server\netstandard1.3\Microsoft.Applications.Events.Server.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: D:\a\1\s\OTelCS.Net461\Sources\OneCollector\obj\Release\Microsoft.Office.Telemetry.OneCollector.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: D:\a\1\s\EventFlags.Net45\Sources\obj\Release\Microsoft.Office.Telemetry.EventFlags.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: D:\a\1\s\EventFlags.Net45\Sources\obj\Release\Microsoft.Office.Telemetry.EventFlags.pdb|A source: 5XpKRbh2k7.exe |
Source: | Binary string: D:\a\1\s\OTelCS.Net461\Sources\TelemetryService\obj\Release\OTelCS.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: mscorlib.ni.pdbRSDS7^3l source: WER2F60.tmp.dmp.3.dr |
Source: | Binary string: C:\b\w\d6337ac2abf63a4b\.repositories\Logging\src\Microsoft.Extensions.Logging.Abstractions\bin\Release\netstandard1.1\Microsoft.Extensions.Logging.Abstractions.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: C:\b\w\d6337ac2abf63a4b\.repositories\Microsoft.Data.Sqlite\src\Microsoft.Data.Sqlite\bin\Release\netstandard1.3\Microsoft.Data.Sqlite.pdb source: 5XpKRbh2k7.exe |
Source: | Binary string: C:\b\w\d6337ac2abf63a4b\.repositories\Logging\src\Microsoft.Extensions.Logging\bin\Release\netstandard1.1\Microsoft.Extensions.Logging.pdb source: 5XpKRbh2k7.exe |
Source: 5XpKRbh2k7.exe, JSONParser.cs | .Net Code: ParseValue |
Source: 5XpKRbh2k7.exe, Program.cs | .Net Code: Main System.Reflection.Assembly.Load(byte[]) |
Source: 5XpKRbh2k7.exe, Program.cs | .Net Code: Main System.Reflection.Assembly.Load(byte[]) |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\5XpKRbh2k7.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: Amcache.hve.3.dr | Binary or memory string: VMware |
Source: Amcache.hve.3.dr | Binary or memory string: VMware Virtual USB Mouse |
Source: Amcache.hve.3.dr | Binary or memory string: vmci.syshbin |
Source: Amcache.hve.3.dr | Binary or memory string: VMware, Inc. |
Source: Amcache.hve.3.dr | Binary or memory string: VMware20,1hbin@ |
Source: Amcache.hve.3.dr | Binary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563 |
Source: Amcache.hve.3.dr | Binary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Amcache.hve.3.dr | Binary or memory string: .Z$c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.3.dr | Binary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.3.dr | Binary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev |
Source: Amcache.hve.3.dr | Binary or memory string: c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.3.dr | Binary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Amcache.hve.3.dr | Binary or memory string: vmci.sys |
Source: Amcache.hve.3.dr | Binary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0 |
Source: Amcache.hve.3.dr | Binary or memory string: vmci.syshbin` |
Source: Amcache.hve.3.dr | Binary or memory string: \driver\vmci,\driver\pci |
Source: Amcache.hve.3.dr | Binary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.3.dr | Binary or memory string: VMware20,1 |
Source: Amcache.hve.3.dr | Binary or memory string: Microsoft Hyper-V Generation Counter |
Source: Amcache.hve.3.dr | Binary or memory string: NECVMWar VMware SATA CD00 |
Source: Amcache.hve.3.dr | Binary or memory string: VMware Virtual disk SCSI Disk Device |
Source: Amcache.hve.3.dr | Binary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom |
Source: Amcache.hve.3.dr | Binary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk |
Source: Amcache.hve.3.dr | Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver |
Source: Amcache.hve.3.dr | Binary or memory string: VMware PCI VMCI Bus Device |
Source: Amcache.hve.3.dr | Binary or memory string: VMware VMCI Bus Device |
Source: Amcache.hve.3.dr | Binary or memory string: VMware Virtual RAM |
Source: Amcache.hve.3.dr | Binary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1 |
Source: Amcache.hve.3.dr | Binary or memory string: vmci.inf_amd64_68ed49469341f563 |