Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\.version | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.runtimeconfig.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.deps.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.SecureString.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.ServicePoint.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Uri.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.CoreLib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Algorithms.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\netstandard.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr\6.0.35\hostfxr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\dotnet.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\LICENSE.txt | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\ThirdPartyNotices.txt | Jump to behavior |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEAGENTINFORMATION/37.9/AGENTPACKAGEAGENTINFORMATI |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEMONITORING/37.8/AGENTPACKAGEMONITORING.ZIP |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGESTREMOTE/23.4/AGENTPACKAGESTREMOTE.ZIP |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A09B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://a6dc35606b2c6816e.awsglobalaccelerator.com |
Source: AteraAgent.exe, 0000000C.00000000.1754536857.000001C5CB452000.00000002.00000001.01000000.0000000F.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA0FC1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD15B1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://acontrol.atera.com/ |
Source: rundll32.exe, 00000004.00000002.1732615847.00000000049C5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA12FA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.00000000046B5000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.1955362018.000001BE62D0F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1CFA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1CF6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D98000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F651000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F68C000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F6E3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://agent-api.atera.com |
Source: rundll32.exe, 00000004.00000002.1732615847.00000000049C5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA12FA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.00000000046B5000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.1955362018.000001BE62D0F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1CF6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D98000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F651000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F68C000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F6E3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://atera-agent-api-eu.westeurope.cloudapp.azure.com |
Source: AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9720000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ca.disig.sk/ca/crl/ca_disig.crl0 |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9D10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA298000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000025.00000002.2562182711.0000000000BF5000.00000002.00000001.01000000.0000001C.sdmp, Arquivo_4593167.msi, SRUsb.exe.1.dr, Microsoft.Win32.TaskScheduler.dll0.24.dr, System.Runtime.Serialization.Json.dll.24.dr, libssl-3.dll.1.dr, System.Diagnostics.Process.dll.24.dr, Microsoft.Extensions.FileSystemGlobbing.dll.24.dr, System.Runtime.InteropServices.dll.24.dr, System.Text.Encodings.Web.dll0.24.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 |
Source: AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA15CC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1283000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD2254000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2978322929.0000016BEA6E0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD21EB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt |
Source: AteraAgent.exe, 0000000C.00000002.1793099468.000001C5E5C8F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA055000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9C1A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B20000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA31E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA29C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976797117.0000016BEA38A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA204000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA309000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA2A2000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA2CB000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A139000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A0B9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt4.0. |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA309000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2978322929.0000016BEA6F6000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A139000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A0B9000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000025.00000002.2562182711.0000000000BF5000.00000002.00000001.01000000.0000001C.sdmp, Arquivo_4593167.msi, SRUsb.exe.1.dr, Microsoft.Win32.TaskScheduler.dll0.24.dr, System.Runtime.Serialization.Json.dll.24.dr, libssl-3.dll.1.dr, System.Diagnostics.Process.dll.24.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B60000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9720000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.1956064131.000001BE7B4B8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA309000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA298000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2978322929.0000016BEA6F6000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2972325371.0000016BE9E4D000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2203027448.000002E967DA9000.00000004.00000020.00020000.00000000.sdmp, cscript.exe, 0000001F.00000003.2084912382.0000022D4CAAB000.00000004.00000020.00020000.00000000.sdmp, cscript.exe, 0000001F.00000002.2087026675.0000022D4CADE000.00000004.00000020.00020000.00000000.sdmp, cscript.exe, 0000001F.00000003.2085700686.0000022D4CADE000.00000004.00000020.00020000.00000000.sdmp, cscript.exe, 0000001F.00000003.2084621827.0000022D4CAA3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0 |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0 |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9D10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA298000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000025.00000002.2562182711.0000000000BF5000.00000002.00000001.01000000.0000001C.sdmp, Arquivo_4593167.msi, SRUsb.exe.1.dr, Microsoft.Win32.TaskScheduler.dll0.24.dr, System.Runtime.Serialization.Json.dll.24.dr, libssl-3.dll.1.dr, System.Diagnostics.Process.dll.24.dr, Microsoft.Extensions.FileSystemGlobbing.dll.24.dr, System.Runtime.InteropServices.dll.24.dr, System.Text.Encodings.Web.dll0.24.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0 |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0= |
Source: AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9C1A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000C.00000002.1793099468.000001C5E5C8F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA15CC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1283000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA055000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9C1A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B20000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA31E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA29C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976797117.0000016BEA38A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD2254000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E5980000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlhttp://crl4.digicert.co |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA309000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2978322929.0000016BEA6F6000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A139000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A0B9000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000025.00000002.2562182711.0000000000BF5000.00000002.00000001.01000000.0000001C.sdmp, Arquivo_4593167.msi, SRUsb.exe.1.dr, Microsoft.Win32.TaskScheduler.dll0.24.dr, System.Runtime.Serialization.Json.dll.24.dr, libssl-3.dll.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E591E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E5904000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: LiteDB.dll.24.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crlL |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E591E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crlb |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E5904000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/l |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02 |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E5980000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlrlCache |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E5980000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com:80/DigiCertTrustedRootG4.crl% |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E5904000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/ |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: AteraAgent.exe, 0000000C.00000002.1793099468.000001C5E5C7C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA15CC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1283000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9C1A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD2254000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD21EB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000C.00000002.1793099468.000001C5E5C8F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA055000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9C1A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B20000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA31E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA29C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976797117.0000016BEA38A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA204000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA309000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA2A2000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA2CB000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A139000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A0B9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl8 |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0= |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/l |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E5980000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlrlCache |
Source: AteraAgent.exe, 00000018.00000002.2972325371.0000016BE9E4D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/ |
Source: AteraAgent.exe, 00000018.00000002.2972325371.0000016BE9E30000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/- |
Source: AteraAgent.exe, 00000018.00000002.2935401771.0000016BD0D96000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/2_h |
Source: AteraAgent.exe, 00000018.00000002.2935401771.0000016BD0D96000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/Pw |
Source: AteraAgent.exe, 00000018.00000002.2972325371.0000016BE9E4D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/Q |
Source: AteraAgent.exe, 00000018.00000002.2935401771.0000016BD0D96000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/VbN |
Source: AteraAgent.exe, 00000018.00000002.2935401771.0000016BD0D96000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/cb |
Source: AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA29C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2935401771.0000016BD0D96000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/e |
Source: AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en |
Source: AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabon |
Source: AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA25C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab |
Source: AteraAgent.exe, 00000018.00000002.2972325371.0000016BE9E74000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA2CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1908e7e |
Source: AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA23D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA204000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA2CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3d5ae80 |
Source: AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA204000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?43a390c |
Source: AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA204000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6c9e1dd |
Source: AteraAgent.exe, 00000018.00000002.2976797117.0000016BEA38A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7160e0b |
Source: AteraAgent.exe, 00000018.00000002.2976797117.0000016BEA38A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9bd3f2b |
Source: AteraAgent.exe, 00000018.00000002.2972325371.0000016BE9E74000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a2b53af |
Source: AteraAgent.exe, 00000018.00000002.2972325371.0000016BE9E74000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b87e0f2 |
Source: AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA25C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cabf |
Source: AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA2CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7160 |
Source: AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA2CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9bd3 |
Source: AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA2CB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c37a |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A0DD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://d17kmd0va0f0mp.cloudfront.net |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://d25btwd9wax8gu.cloudfront.net |
Source: AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000000.1924528514.000001BE62232000.00000002.00000001.01000000.00000016.sdmp | String found in binary or memory: http://dl.google.com/googletalk/googletalk-setup.exe |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A0DD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://download.splashtop.com |
Source: AgentPackageAgentInformation.exe, 00000014.00000002.1954314035.000001BE6236E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.microsoft.c |
Source: AgentPackageAgentInformation.exe, 00000014.00000002.1954314035.000001BE6236E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.microsoft.ctain |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2669791407.00000217326D0000.00000002.00000001.01000000.00000021.sdmp | String found in binary or memory: http://james.newtonking.com/projects/json |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A09B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://my.splashtop.com |
Source: NLog.dll.24.dr | String found in binary or memory: http://nlog-project.org/dummynamespace/ |
Source: NLog.dll.24.dr | String found in binary or memory: http://nlog-project.org/ws/ |
Source: NLog.dll.24.dr | String found in binary or memory: http://nlog-project.org/ws/3 |
Source: NLog.dll.24.dr | String found in binary or memory: http://nlog-project.org/ws/5 |
Source: NLog.dll.24.dr | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverOneWayServer/ProcessLogMessages |
Source: NLog.dll.24.dr | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverServer/ProcessLogMessagesResponsep |
Source: NLog.dll.24.dr | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverServer/ProcessLogMessagesT |
Source: NLog.dll.24.dr | String found in binary or memory: http://nlog-project.org/ws/T |
Source: AteraAgent.exe, 00000018.00000002.2978322929.0000016BEA6E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digi |
Source: AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9800000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/ |
Source: AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9800000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/3 |
Source: AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B20000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2267142526.0000020AA082C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2977989591.0000016BEA6C7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2978250326.0000016BEA6DB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rh |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxX |
Source: AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9800000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/X |
Source: AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9800000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/l- |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E5904000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/lN |
Source: AteraAgent.exe, 0000000C.00000002.1793099468.000001C5E5C8F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA15CC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1283000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA055000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9C1A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B20000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA31E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA29C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976797117.0000016BEA38A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD2254000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9720000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.1956064131.000001BE7B4B8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA309000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA298000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2978322929.0000016BEA6F6000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2972325371.0000016BE9E4D000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2203027448.000002E967DA9000.00000004.00000020.00020000.00000000.sdmp, cscript.exe, 0000001F.00000003.2084912382.0000022D4CAAB000.00000004.00000020.00020000.00000000.sdmp, cscript.exe, 0000001F.00000002.2087026675.0000022D4CADE000.00000004.00000020.00020000.00000000.sdmp, cscript.exe, 0000001F.00000003.2085700686.0000022D4CADE000.00000004.00000020.00020000.00000000.sdmp, cscript.exe, 0000001F.00000003.2084621827.0000022D4CAA3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0A |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9D10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA298000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000025.00000002.2562182711.0000000000BF5000.00000002.00000001.01000000.0000001C.sdmp, Arquivo_4593167.msi, SRUsb.exe.1.dr, Microsoft.Win32.TaskScheduler.dll0.24.dr, System.Runtime.Serialization.Json.dll.24.dr, libssl-3.dll.1.dr, System.Diagnostics.Process.dll.24.dr, Microsoft.Extensions.FileSystemGlobbing.dll.24.dr, System.Runtime.InteropServices.dll.24.dr, System.Text.Encodings.Web.dll0.24.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://ocsp.digicert.com0K |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://ocsp.digicert.com0N |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://ocsp.digicert.com0O |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA309000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2978322929.0000016BEA6F6000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A139000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A0B9000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000025.00000002.2562182711.0000000000BF5000.00000002.00000001.01000000.0000001C.sdmp, Arquivo_4593167.msi, SRUsb.exe.1.dr, Microsoft.Win32.TaskScheduler.dll0.24.dr, System.Runtime.Serialization.Json.dll.24.dr, libssl-3.dll.1.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: AteraAgent.exe, 00000018.00000002.2978322929.0000016BEA6E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedG4CodeSigning |
Source: AteraAgent.exe, 0000000C.00000002.1793099468.000001C5E5C6E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B60000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA269000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2978322929.0000016BEA6E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRS |
Source: AteraAgent.exe, 00000018.00000002.2978250326.0000016BEA6DB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedRootG4.crt |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E5955000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com:80/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF |
Source: AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E5904000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertAssuredIDRootCA.crl |
Source: AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B76000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2972325371.0000016BE9E4D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.cr |
Source: AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB97D3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA269000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crlV |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ocsp.thawte.com0 |
Source: AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9CC6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://pki.digidentity.eu/validatie0 |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ps.atera.com |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1592000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1CC3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D78000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ps.pndsn.com |
Source: AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://repository.swisssign.com/0 |
Source: xdnup.dll.1.dr | String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0 |
Source: xdnup.dll.1.dr | String found in binary or memory: http://s2.symcb.com0 |
Source: AteraAgent.exe, 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org |
Source: AteraAgent.exe, 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp, System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/ |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.Collections.GenericJ |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.IO |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.Runtime.Serialization |
Source: AteraAgent.exe, 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.ServiceProcess |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.Xml |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/SystemV |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/SystemY |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/dhttp://schemas.datacontract.org/2004/07/System.XmlRhttp://w |
Source: NLog.dll.24.dr | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: rundll32.exe, 00000004.00000002.1732615847.0000000004901000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1732615847.00000000049A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA0FC1000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.00000000045F1000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.0000000004694000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.1955362018.000001BE62C63000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD15B1000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F491000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F6BF000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.0000021719FB8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: xdnup.dll.1.dr | String found in binary or memory: http://sv.symcb.com/sv.crl0a |
Source: xdnup.dll.1.dr | String found in binary or memory: http://sv.symcb.com/sv.crt0 |
Source: xdnup.dll.1.dr | String found in binary or memory: http://sv.symcd.com0& |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: http://wixtoolset.org |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004815000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047CC000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D47000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000440E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004815000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047CC000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D47000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000440E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/news/ |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004815000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047CC000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D47000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000440E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/releases/ |
Source: AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.ancert.com/cps0 |
Source: AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9CC6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.cert.fnmt.es/dpcs/0 |
Source: AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9CC6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.certplus.com/CRL/class3TS.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9720000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.datev.de/zertifikat-policy-int0 |
Source: AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9720000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.datev.de/zertifikat-policy-std0 |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA15CC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1283000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD2254000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD21EB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1793099468.000001C5E5C8F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1790492966.000001C5E58A0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA055000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9C1A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2281496750.0000020AB9B20000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA31E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA29C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA204000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2976304470.0000016BEA309000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2974355709.0000016BEA2A2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPSp |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPSstem |
Source: AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9720000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.disig.sk/ca/crl/ca_disig.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2279102001.0000020AB9720000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.disig.sk/ca0f |
Source: AteraAgent.exe, 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.e-me.lv/repository0 |
Source: AteraAgent.exe, 0000000D.00000002.2282825260.0000020AB9CE0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.eme.lv/repository0 |
Source: AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA024000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.pki.admin.ch/policy/CPS_2_16_756_1_17_3_21_1.pdf0 |
Source: xdnup.dll.1.dr | String found in binary or memory: http://www.symauth.com/cps0( |
Source: xdnup.dll.1.dr | String found in binary or memory: http://www.symauth.com/rpa00 |
Source: AteraAgent.exe, 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.o |
Source: AteraAgent.exe, 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.oh |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F72A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.P |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D98000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.PH |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F6BF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.Pjo |
Source: rundll32.exe, 00000004.00000002.1732615847.00000000049A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.0000000004694000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.aterD |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004815000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047CC000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1732615847.0000000004901000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1732615847.00000000049A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D47000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA0FC1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA12FA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000440E000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.00000000045F1000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.0000000004694000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.1955362018.000001BE62C63000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1CF2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D02000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1695000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D78000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F651000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F68C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004815000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047CC000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1732615847.0000000004901000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1732615847.00000000049A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D47000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000440E000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.00000000045F1000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.0000000004694000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/ |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F72A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Prh( |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Pro |
Source: AgentPackageAgentInformation.exe, 00000014.00000002.1955362018.000001BE62C63000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F651000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F68C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004815000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047CC000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1732615847.0000000004901000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1732615847.00000000049A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D47000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000440E000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.00000000045F1000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.0000000004694000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/ |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AcknowledgeCommands |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1068000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D02000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D78000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AgentStarting |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA12FA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AgentStarting) |
Source: AgentPackageAgentInformation.exe, 00000014.00000002.1955362018.000001BE62C63000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/CommandResult |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10D4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1044000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1CF2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD161C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetCommands |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10D4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1068000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetCommandsFallback |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA0FC1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetEnvironmentStatus |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D98000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetRecurrin |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA0FC1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1068000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D98000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetRecurringPackages |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetRecurringPackagesseTasH |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1695000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/Trace |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F6BF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/ |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F491000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F6BF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/script-based |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F72A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/guiComm |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F523000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F72A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/guiCommandResult |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F651000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2184094049.000002E94F68C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/recurringCommandResult |
Source: rundll32.exe, 00000004.00000002.1732615847.0000000004901000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1732615847.00000000049A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.00000000045F1000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.0000000004694000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/track-event |
Source: rundll32.exe, 00000004.00000002.1732615847.00000000049E6000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1843416546.00000000046D6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/track-event; |
Source: System.Private.CoreLib.dll.1.dr | String found in binary or memory: https://aka.ms/GlobalizationInvariantMode |
Source: System.Diagnostics.EventLog.dll.24.dr, System.Private.CoreLib.dll.1.dr | String found in binary or memory: https://aka.ms/binaryformatter |
Source: System.Private.CoreLib.dll.1.dr | String found in binary or memory: https://aka.ms/dotnet-illink/com |
Source: System.Diagnostics.EventLog.dll.24.dr | String found in binary or memory: https://aka.ms/dotnet-warnings/ |
Source: System.Diagnostics.EventLog.dll.24.dr | String found in binary or memory: https://aka.ms/serializationformat-binary-obsolete |
Source: xdnup.dll.1.dr | String found in binary or memory: https://d.symcb.com/cps0% |
Source: xdnup.dll.1.dr | String found in binary or memory: https://d.symcb.com/rpa0 |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A0C1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://download.splashtop.com |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A0C1000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A0BD000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A09B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://download.splashtop.com/csrs/Splashtop_Streamer_Win_DEPLOY_INSTALLER_v3.7.2.0.exe |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2280646482.0000020AB9882000.00000002.00000001.01000000.0000001E.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.1955108650.000001BE62AF2000.00000002.00000001.01000000.00000019.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2669791407.00000217326D0000.00000002.00000001.01000000.00000021.sdmp | String found in binary or memory: https://github.com/JamesNK/Newtonsoft.Json |
Source: Microsoft.Win32.TaskScheduler.dll0.24.dr | String found in binary or memory: https://github.com/dahall/taskscheduler |
Source: System.Diagnostics.DiagnosticSource.dll1.24.dr | String found in binary or memory: https://github.com/dotnet/corefx/tree/30ab651fcb4354552bd4891619a0bdd81e0ebdbf |
Source: System.Diagnostics.DiagnosticSource.dll1.24.dr | String found in binary or memory: https://github.com/dotnet/corefx/tree/30ab651fcb4354552bd4891619a0bdd81e0ebdbf8 |
Source: System.IO.FileSystem.Primitives.dll.1.dr, System.IO.IsolatedStorage.dll.1.dr, System.Security.Cryptography.Cng.dll.1.dr, System.Reflection.Emit.dll.1.dr, System.Xml.XDocument.dll.1.dr, System.Private.DataContractSerialization.dll.1.dr, Microsoft.CSharp.dll.1.dr, Microsoft.Extensions.FileSystemGlobbing.dll.24.dr, System.Diagnostics.EventLog.dll.24.dr, System.Threading.Tasks.Dataflow.dll.1.dr, System.Text.Encodings.Web.dll0.24.dr, System.Reflection.Primitives.dll.1.dr, System.Data.Common.dll.1.dr, System.Runtime.Serialization.Json.dll.1.dr | String found in binary or memory: https://github.com/dotnet/runtime |
Source: System.Threading.Tasks.Dataflow.dll.1.dr | String found in binary or memory: https://github.com/dotnet/runtimew |
Source: AteraAgent.exe, 0000000D.00000002.2284169189.0000020AB9F22000.00000002.00000001.01000000.0000001F.sdmp | String found in binary or memory: https://github.com/icsharpcode/SharpZipLib |
Source: LiteDB.dll.24.dr | String found in binary or memory: https://github.com/mbdavid/LiteDB |
Source: System.Data.Common.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1187 |
Source: Microsoft.CSharp.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1416. |
Source: Microsoft.CSharp.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1906. |
Source: System.Data.Common.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1981 |
Source: System.Private.CoreLib.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/378 |
Source: System.Private.CoreLib.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/pull/649 |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2648816776.000002171A096000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.0000021719FB8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://my.splashtop.com |
Source: AgentPackageSTRemote.exe, 00000021.00000000.2010019478.0000021719512000.00000002.00000001.01000000.0000001A.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.0000021719FB8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://my.splashtop.com/csrs/win |
Source: NLog.dll.24.dr | String found in binary or memory: https://nlog-project.org/ |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/a |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/ag |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10D4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageA |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAg |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAge |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAgentI |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageMonitoring/0.40/AgentPackageMonitoring.z |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10C4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageSTRemote/2.3/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageSTRemote/2.3/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.Availability/0.16/Agent.Package.Availability.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.IotPoc/0.2/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageAgentInformation/37.9/AgentPackageAgentInformation |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14D5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMonitoring/37.8/AgentPackageMonitoring.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageNetworkDiscovery/13.0/AgentPackageNetworkDiscovery |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageRuntimeInstaller/1.5/AgentPackageRuntimeInstaller. |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10C4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSTRemote/23.4/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageTaskScheduler/13.0/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Availability/0.16/Agent.Package.Availability.z |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.IotPoc/0.2/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageADRemote/6.0/AgentPackageADRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageAgentInformation/37.9/AgentPackageAgentInformati |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageHeartbeat/17.14/AgentPackageHeartbeat.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageHeartbeat/17.14/AgentPackageHeartbeat.zipp |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageInternalPoller/23.8/AgentPackageInternalPoller.z |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMarketplace/1.6/AgentPackageMarketplace.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip?KKgGC |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14D5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageNetworkDiscovery/23.9/AgentPackageNetworkDiscove |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageOsUpdates/20.0/AgentPackageOsUpdates.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageProgramManagement/25.8/AgentPackageProgramManage |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageRuntimeInstaller/1.6/AgentPackageRuntimeInstalle |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10C4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip?KKgGC7fCc |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSystemTools/27.6/AgentPackageSystemTools.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTaskScheduler/17.2/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTicketing/29.9/AgentPackageTicketing.zip |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTicketing/29.9/AgentPackageTicketing.zip?KKgGC7f |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageUpgradeAgent/27.2/AgentPackageUpgradeAgent.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageWindowsUpdate/24.6/AgentPackageWindowsUpdate.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.Availability/13.0/Agent.Package.Availability.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.IotPoc/13.0/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.Watchdog/13.0/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageAgentInformation/22.7/AgentPackageAgentInformation |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageMonitoring/22.0/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageNetworkDiscovery/15.0/AgentPackageNetworkDiscovery |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageRuntimeInstaller/13.0/AgentPackageRuntimeInstaller |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageSTRemote/16.0/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageTaskScheduler/13.1/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000000.2010019478.0000021719512000.00000002.00000001.01000000.0000001A.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2648816776.0000021719FB8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/installers/splashtop/win/SplashtopStreamer.exe |
Source: AteraAgent.exe, 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000000.2010019478.0000021719512000.00000002.00000001.01000000.0000001A.sdmp | String found in binary or memory: https://ps.atera.com/installers/splashtop/win/SplashtopStreamer.exepUsers/Shared/Splashtop |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1592000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D0E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D98000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D02000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1592000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10D4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1068000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D0E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1CC3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD161C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1C7A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D98000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D02000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D78000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10D4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=00370d56-8b21-43a9-8b87-a8ec77571e56 |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1068000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=0efe0bbf-2a0e-40d8-965f-19f51f0fd321 |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1592000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=2bfbcf15-78c5-42b3-a888-e57cf083e16d |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=737ec693-90a8-4422-9ac8-a4ec4dd18ff5 |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D0E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=abea1582-463a-4a7f-add0-13f90d8f2650 |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA10D4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=b8910c6f-67a0-4f27-ab84-5ffd997cd0c5 |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=d356e0ff-7cf6-451a-abfd-493cb798864d |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD161C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=da8a8aee-d717-4843-aaf8-93981205c3dc |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=e67ebcbd-5956-47bb-95bb-73cf0832e6de |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1CFA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2 |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D78000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/presence/sub_key/sub-c-a02ceca8 |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D78000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/presence/sub_key/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/channel/bc2f6fef |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/sub-c-a02ceca8-a958-11e5-b |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD161C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/sub-c-a02ceca8-a958-11e5-bd8c- |
Source: AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/bc2f6fef-7e04-492a-b3 |
Source: AteraAgent.exe, 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1C7A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1D98000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2940646679.0000016BD1695000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/bc2f6fef-7e04-492a-b3cb |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, Arquivo_4593167.msi | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.newtonsoft.com/json |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2669791407.00000217326D0000.00000002.00000001.01000000.00000021.sdmp | String found in binary or memory: https://www.newtonsoft.com/jsonschema |
Source: NLog.dll.24.dr | String found in binary or memory: https://www.nuget.org/packages/NLog.Web.AspNetCore |
Source: rundll32.exe, 00000003.00000003.1679439512.0000000004846000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1691787592.00000000047FD000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1736086119.0000000004D78000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2280646482.0000020AB9882000.00000002.00000001.01000000.0000001E.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1796836889.000000000443F000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.1955108650.000001BE62AF2000.00000002.00000001.01000000.00000019.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2669791407.00000217326D0000.00000002.00000001.01000000.00000021.sdmp | String found in binary or memory: https://www.nuget.org/packages/Newtonsoft.Json.Bson |
Source: PreVerCheck.exe, 00000025.00000002.2562182711.0000000000BF5000.00000002.00000001.01000000.0000001C.sdmp, libssl-3.dll.1.dr | String found in binary or memory: https://www.openssl.org/H |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Arquivo_4593167.msi" | |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 0B94C8984E2657846CB3FC17409B05D4 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIC672.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4507343 2 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.GenerateAgentId | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIC961.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4508140 6 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiStart | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIDCAB.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4512968 10 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ShouldContinueInstallation | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 987DB95BE1D08D72E3D28015C548C789 E Global\MSI0000 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\net.exe "NET" STOP AteraAgent | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 STOP AteraAgent | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "TaskKill.exe" /f /im AteraAgent.exe | |
Source: C:\Windows\SysWOW64\taskkill.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="000111.financeiro@yamahaconcessionaria.com.br" /CompanyId="1" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="" /AccountId="001Q300000LlkxmIAB" /AgentId="bc2f6fef-7e04-492a-b3cb-1c03cb0df5b2" | |
Source: unknown | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIF4AD.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4519093 32 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiEnd | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" bc2f6fef-7e04-492a-b3cb-1c03cb0df5b2 "dda45391-8ca1-4116-81d7-6a5f04c3dc70" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 001Q300000LlkxmIAB | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" bc2f6fef-7e04-492a-b3cb-1c03cb0df5b2 "927926aa-335a-417d-b375-138a84c77d14" agent-api.atera.com/Production 443 or8ixLi90Mf "identified" 001Q300000LlkxmIAB | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" bc2f6fef-7e04-492a-b3cb-1c03cb0df5b2 "e24a5d52-0d16-40c8-ae18-af372363c3dc" agent-api.atera.com/Production 443 or8ixLi90Mf "generalinfo fromGui" 001Q300000LlkxmIAB | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\System32\cscript.exe cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\System32\sppsvc.exe C:\Windows\system32\sppsvc.exe | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe" bc2f6fef-7e04-492a-b3cb-1c03cb0df5b2 "c7045ac8-f19b-40af-bcd9-2d8df64c2185" agent-api.atera.com/Production 443 or8ixLi90Mf "install eyJSbW1Db2RlIjoiaFpDREZQaEs3NW1KIn0=" 001Q300000LlkxmIAB | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k smphost | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\Temp\SplashtopStreamer.exe "C:\Windows\TEMP\SplashtopStreamer.exe" prevercheck /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Process created: C:\Windows\Temp\unpack\PreVerCheck.exe "C:\Windows\Temp\unpack\PreVerCheck.exe" /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Process created: C:\Windows\SysWOW64\msiexec.exe msiexec /norestart /i "setup.msi" /qn /l*v "C:\Windows\TEMP\PreVer.log.txt" CA_EXTPATH=1 USERINFO="sec_opt=0,confirm_d=0,hidewindow=1" | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 556B5128AD7072E16BEB10DB90B1A40C E Global\MSI0000 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{E00D6CF4-4FC3-431C-B643-8FF5D1691F3C} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{92D3031C-81C4-4FED-8F50-F5E3BE9F3612} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{4C499929-14EA-4E52-BDA5-131742626400} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{6385CD88-DCB3-4881-A482-8EE7F96DDDE3} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{8ABF8E23-F9FD-49C3-8B2D-36EBD8434563} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{4103781B-B841-4FC0-AA1E-5FD5FA8D8AE8} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{FB3E51D0-455D-47D0-B21A-C3DC48DCD266} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{AA5AA93B-7BA4-4056-819A-23A48FF3891F} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{035C7190-A369-4041-A248-C0E4DB43C54F} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{B627E9BE-EB25-4498-B44A-CDE0D79185EC} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe /C "taskkill.exe /F /IM SRServer.exe /T" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe taskkill.exe /F /IM SRServer.exe /T | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe /C "taskkill.exe /F /IM SRApp.exe /T" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 0B94C8984E2657846CB3FC17409B05D4 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 987DB95BE1D08D72E3D28015C548C789 E Global\MSI0000 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="000111.financeiro@yamahaconcessionaria.com.br" /CompanyId="1" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="" /AccountId="001Q300000LlkxmIAB" /AgentId="bc2f6fef-7e04-492a-b3cb-1c03cb0df5b2" | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 556B5128AD7072E16BEB10DB90B1A40C E Global\MSI0000 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIC672.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4507343 2 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.GenerateAgentId | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIC961.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4508140 6 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiStart | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIDCAB.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4512968 10 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ShouldContinueInstallation | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIF4AD.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4519093 32 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiEnd | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\net.exe "NET" STOP AteraAgent | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "TaskKill.exe" /f /im AteraAgent.exe | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 STOP AteraAgent | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" bc2f6fef-7e04-492a-b3cb-1c03cb0df5b2 "dda45391-8ca1-4116-81d7-6a5f04c3dc70" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 001Q300000LlkxmIAB | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" bc2f6fef-7e04-492a-b3cb-1c03cb0df5b2 "927926aa-335a-417d-b375-138a84c77d14" agent-api.atera.com/Production 443 or8ixLi90Mf "identified" 001Q300000LlkxmIAB | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" bc2f6fef-7e04-492a-b3cb-1c03cb0df5b2 "e24a5d52-0d16-40c8-ae18-af372363c3dc" agent-api.atera.com/Production 443 or8ixLi90Mf "generalinfo fromGui" 001Q300000LlkxmIAB | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe" bc2f6fef-7e04-492a-b3cb-1c03cb0df5b2 "c7045ac8-f19b-40af-bcd9-2d8df64c2185" agent-api.atera.com/Production 443 or8ixLi90Mf "install eyJSbW1Db2RlIjoiaFpDREZQaEs3NW1KIn0=" 001Q300000LlkxmIAB | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cscript.exe cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\Temp\SplashtopStreamer.exe "C:\Windows\TEMP\SplashtopStreamer.exe" prevercheck /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Process created: C:\Windows\Temp\unpack\PreVerCheck.exe "C:\Windows\Temp\unpack\PreVerCheck.exe" /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Process created: C:\Windows\SysWOW64\msiexec.exe msiexec /norestart /i "setup.msi" /qn /l*v "C:\Windows\TEMP\PreVer.log.txt" CA_EXTPATH=1 USERINFO="sec_opt=0,confirm_d=0,hidewindow=1" | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{E00D6CF4-4FC3-431C-B643-8FF5D1691F3C} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{92D3031C-81C4-4FED-8F50-F5E3BE9F3612} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{4C499929-14EA-4E52-BDA5-131742626400} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{6385CD88-DCB3-4881-A482-8EE7F96DDDE3} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{8ABF8E23-F9FD-49C3-8B2D-36EBD8434563} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{4103781B-B841-4FC0-AA1E-5FD5FA8D8AE8} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{FB3E51D0-455D-47D0-B21A-C3DC48DCD266} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{AA5AA93B-7BA4-4056-819A-23A48FF3891F} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{035C7190-A369-4041-A248-C0E4DB43C54F} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{B627E9BE-EB25-4498-B44A-CDE0D79185EC} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe /C "taskkill.exe /F /IM SRServer.exe /T" | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe /C "taskkill.exe /F /IM SRApp.exe /T" | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe C:\Windows\TEMP\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\_isA1FD.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{4103781B-B841-4FC0-AA1E-5FD5FA8D8AE8} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe taskkill.exe /F /IM SRServer.exe /T | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msihnd.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srclient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: spp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vssapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vsstrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: riched20.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: usp10.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msls31.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: edputil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wintypes.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: appresolver.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: bcp47langs.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: slc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sppc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: edputil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wintypes.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: appresolver.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: bcp47langs.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: slc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sppc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wscapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wtsapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winsta.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: devobj.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: napinsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wshbth.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: nlaapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptnet.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: smphost.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: mispace.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: sxshared.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wmiclnt.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: devobj.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wevtapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: virtdisk.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: bcd.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: fltlib.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: cscapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: fmifs.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: ulib.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: ifsutil.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: healthapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: healthapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wsp_fs.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: netapi32.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dsrole.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: sscore.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: ntdsapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wsp_sr.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: tdh.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wsp_health.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: healthapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: healthapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: healthapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: healthapi.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: wtsapi32.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: version.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: wldp.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: propsys.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: profapi.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: vaultcli.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: edputil.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: netutils.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\.version | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.runtimeconfig.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.deps.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.SecureString.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.ServicePoint.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Uri.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.CoreLib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Algorithms.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\netstandard.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr\6.0.35\hostfxr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\dotnet.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\LICENSE.txt | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\ThirdPartyNotices.txt | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PkgHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.X509Certificates.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppAnnotation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\WBAppVidRec.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIC961.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI172D.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIC672.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x86.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIFB85.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRManager.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\dbghelp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSelfSignCertUtil.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\avutil-55.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppBrowser.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Algorithms.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\legacy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIC961.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIC961.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\64bits\stgamepad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomCtrl32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIA0BF.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIDCAB.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDetect.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVirtualDisplay.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiCaptor.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI9F94.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIDCAB.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\dotnet.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI6833.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIB5CE.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE0C6.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcelt-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsbVhciCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUACCheck.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIDCAB.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x64\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI1DD5.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcrypto-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\Mirror2Extend.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Handles.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIF4AD.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libx264-116.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\ARPPRODUCTICON.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIF4AD.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\netstandard.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIF4AD.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.InteropServices.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIC961.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stvideo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppBS.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libmp4v2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppED.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Polly.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperExx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppPB.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIDF3E.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\PrnPort.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI9FF2.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Dapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.SecureString.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\qrcodelib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsb.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x64\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI12F6.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIDCAB.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SROpus.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\64bits\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264Wrapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\32bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\swresample-2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIF4AD.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRApp.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\sthid.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\hidkmdf.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrlEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIC672.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\setupdrv.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\32bits\stvspk.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\hidkmdf.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK_x86.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIC672.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\64bits\stvspk.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\32bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\SetupUtil.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\host\fxr\6.0.35\hostfxr.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsbVhciCtrl32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI65BF.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.CoreLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI6457.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppCam.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI6738.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.SecureString.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIDEEF.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppFileHound.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI3352.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAdemWrapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Uri.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAudioChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIC672.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Elevator.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Algorithms.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\NvFBC.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PinShortCut.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x64\SRWacomUtil64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcurl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\sthid.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIC961.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdateInstall.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUtility.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeatMini.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomUtil32.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIDCAB.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI6B72.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdwmark.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Data.SQLite.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\SharpSnmpLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsb.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIF4AD.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Polly.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\fips.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\WdfCoInstaller01009.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\choco.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\stgamepad.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Principal.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAudioResample.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x86\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\WdfCoInstaller01009.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.ServicePoint.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\amf-vcedem-win32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stvideo.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Pubnub.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x64\SRWacomCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Primitives.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIC672.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\OpenHardwareMonitorLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\taskkill.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{67C8555A-C946-4EFE-94E2-31ABF84FC74E}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\CredentialManagement.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppAnnotation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Interop.WUApiLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\NLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Data.SQLite.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\log4net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.Concurrent.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI172D.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIC672.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIFB85.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.ThreadPool.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{87AA7DD5-455D-434C-80E8-C02BAF62BC90}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.FileExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\my_setup.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\avutil-55.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\win\lib\net6.0\System.Diagnostics.EventLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Atera.Agent.Package.Infrastructure.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppBrowser.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Algorithms.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingTrayTMP.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIC961.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.ServiceProcess.ServiceController.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.CompilerServices.VisualC.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Console.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Process.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIA0BF.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Microsoft.Win32.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileSystemGlobbing.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.EventLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingNotifications.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiCaptor.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI9F94.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.TextWriterTraceListener.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Compression.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI6833.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcelt-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUACCheck.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Globalization.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIDCAB.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI1DD5.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Text.RegularExpressions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\Mirror2Extend.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\AgentPackageHeartbeat.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.Sinks.File.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF4AD.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\StructureMap.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libx264-116.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\ARPPRODUCTICON.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\zh-Hant\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{6F76B734-D534-49DB-8B2F-C42ABA90C4F4}\ISRT.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF4AD.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Resources.Writer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.InteropServices.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\system32\SRCredentialProvider.dll (copy) | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIC961.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XPath.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.EventSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppBS.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libmp4v2.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\System32\SRCEF21.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppED.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Buffers.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\QRCoder.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperExx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppPB.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.Utils.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Dapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.Console.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\CredentialManagement.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.SecureString.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\fr\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsb.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Dropped PE file which has not been started: C:\Windows\Temp\unpack\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x64\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Tracing.dll | Jump to dropped file |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Dropped PE file which has not been started: C:\Windows\Temp\unpack\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIDCAB.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SROpus.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\64bits\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF4AD.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\CredentialManagement.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\RunScriptAsUser.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.Watcher.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\win\lib\net6.0\System.ServiceProcess.ServiceController.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\setupdrv.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\32bits\stvspk.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\LiteDB.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Options.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\hidkmdf.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIC672.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK_x86.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\SetupUtil.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\host\fxr\6.0.35\hostfxr.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsbVhciCtrl32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Overlapped.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\AgentPackageTicketing.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.UnmanagedMemoryStream.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Binder.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{3302634C-E4F1-4E20-978A-65EAB068911F}\ISRT.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\AgentPackageSystemTools.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\UserDetections.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI6738.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XPath.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Drawing.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIDEEF.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppFileHound.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Timer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\StructureMap.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\chocolatey.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\EO.WebBrowser.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ComponentModel.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI3352.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.DriveInfo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAudioChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIC672.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileProviders.Physical.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcurl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\sthid.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Agent.Package.Watchdog.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUtility.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ComponentModel.EventBasedAsync.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomUtil32.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.DependencyInjection.Abstractions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\SharpSnmpLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.DependencyInjection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsb.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF4AD.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Polly.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\fips.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.Extensions.Logging.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\x64\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Primitives.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{3302634C-E4F1-4E20-978A-65EAB068911F}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.Specialized.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\stgamepad.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Globalization.Calendars.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x86\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\WdfCoInstaller01009.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Microsoft.Win32.TaskScheduler.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Data.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x64\SRWacomCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIC672.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PkgHelper.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.X509Certificates.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\StructureMap.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\AgentPackageRuntimeInstaller.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\AgentPackageUpgradeAgent.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.UserSecrets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\WBAppVidRec.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIC961.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x86.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRManager.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\AgentPackageInternalPoller.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSelfSignCertUtil.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{2E57EE32-498E-460F-A7F9-DBF7259DFF60}\ISRT.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Diagnostics.EventLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Globalization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\legacy.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIC961.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Options.ConfigurationExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\64bits\stgamepad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomCtrl32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIDCAB.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDetect.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVirtualDisplay.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIDCAB.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\dotnet.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Atera.AgentCommunication.Models.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE0C6.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIB5CE.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsbVhciCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Hosting.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe TID: 3868 | Thread sleep time: -30000s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1456 | Thread sleep time: -60000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 6036 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 6412 | Thread sleep count: 2349 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 6128 | Thread sleep count: 7356 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 4476 | Thread sleep time: -23058430092136925s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 4476 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 6036 | Thread sleep time: -220000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 4464 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 3604 | Thread sleep time: -180000s >= -30000s | |
Source: C:\Windows\SysWOW64\rundll32.exe TID: 5480 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7136 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1908 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 3068 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 2132 | Thread sleep count: 8078 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 2132 | Thread sleep count: 1444 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7108 | Thread sleep count: 38 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7108 | Thread sleep time: -35048813740048126s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 2140 | Thread sleep time: -220000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1376 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 2792 | Thread sleep time: -180000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 6460 | Thread sleep count: 4117 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 5436 | Thread sleep count: 5755 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -20291418481080494s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -599875s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -599766s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -599656s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -599547s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -599433s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -599328s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -599219s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -599109s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -599000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -598890s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -598781s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -598672s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -598562s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -598453s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -598344s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -598234s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -598125s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -598016s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -597906s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -597797s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -597688s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -597563s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -597438s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -597327s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -597219s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -597094s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -596984s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -596875s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -596766s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -596656s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -596547s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -596437s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -596328s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -596219s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -596094s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -595984s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -595871s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7368 | Thread sleep time: -595766s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep count: 44 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -40582836962160988s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7216 | Thread sleep count: 6283 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -599890s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -599778s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7216 | Thread sleep count: 3519 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -599653s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -599265s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -598922s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -598706s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -598578s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -598468s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -598359s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -598250s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -598138s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -598025s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -597919s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -597812s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -597702s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -597593s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -597483s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -597347s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -597218s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -597109s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -596987s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -596859s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -596745s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -596422s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -596047s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -595797s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -595655s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -595546s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -595437s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -595328s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -595215s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -595030s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -594921s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -594810s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -594687s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -594577s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -594468s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -594356s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -594249s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -594138s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -594031s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -593921s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -593806s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -593703s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -593593s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -593468s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -593359s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -593249s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -593138s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -593031s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -592921s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -592811s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -592702s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -592593s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7212 | Thread sleep time: -592484s >= -30000s | |
Source: C:\Windows\Temp\SplashtopStreamer.exe TID: 7388 | Thread sleep time: -33000s >= -30000s | |
Source: C:\Windows\SysWOW64\msiexec.exe TID: 7536 | Thread sleep time: -60000s >= -30000s | |
Source: Yara match | File source: 20.2.AgentPackageAgentInformation.exe.1be62a40000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 12.0.AteraAgent.exe.1c5cb450000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 20.0.AgentPackageAgentInformation.exe.1be62230000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 33.0.AgentPackageSTRemote.exe.21719510000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0000000D.00000002.2266876260.0000020AA05F0000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2916644902.0000004DD77F5000.00000004.00000010.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA15CC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2267142526.0000020AA07E1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2281496750.0000020AB9B88000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2179995487.000002E94EAE1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.1970238618.000002696E998000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA1592000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2184094049.000002E94F6BB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2974355709.0000016BEA29C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2644540988.000002171967C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1790492966.000001C5E5980000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1C42000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.1955362018.000001BE62C53000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1793012052.000001C5E5B60000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2672625808.0000021732811000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2935401771.0000016BD0D6D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA1283000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2206158038.000002E967EE6000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2644865064.000002171968E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD21E8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2184094049.000002E94F5F3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.1954314035.000001BE62321000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2648442320.0000021719940000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.1969655757.0000026900083000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA1224000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2179995487.000002E94EB24000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2268866315.0000020AA09F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA15CA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2648816776.000002171A0C1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2281496750.0000020AB9BF8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA1248000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.1954927501.000001BE62670000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1E96000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD161C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2972325371.0000016BE9F09000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.1954314035.000001BE622E0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2977086603.0000016BEA395000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2284391960.0000020ABA010000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2284530443.0000020ABA03C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.1954998107.000001BE62A42000.00000002.00000001.01000000.00000018.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2284530443.0000020ABA070000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.1970238618.000002696E990000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001F.00000002.2086909400.0000022D4CA70000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2089827549.000002332A61B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1BEF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD2252000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.1970116257.000002696E940000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD15B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1789701258.000001C5CD182000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1794278518.00007FFD9B694000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD2254000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1789701258.000001C5CD205000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1C7A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2935178142.0000016BD0CD0000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000000.1924528514.000001BE62232000.00000002.00000001.01000000.00000016.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1789419276.000001C5CB820000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1789701258.000001C5CD202000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1C14000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2935401771.0000016BD0D4D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2267142526.0000020AA07DB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000000.1754536857.000001C5CB452000.00000002.00000001.01000000.0000000F.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.1970238618.000002696EA14000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD20A4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2263664624.000000CBDA8F5000.00000004.00000010.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2644865064.00000217196FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2644865064.00000217196BA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1788731094.000001C5CB54C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA1349000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000003.1796836889.000000000440E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA10D4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000005.00000003.1736086119.0000000004D47000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000003.1992596648.000002332A8C0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2282825260.0000020AB9C1A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2089827549.000002332A633000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2198254091.000002E967C21000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1C5C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA13CF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2974355709.0000016BEA23D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000002.1843416546.0000000004694000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2974355709.0000016BEA204000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA1168000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD2175000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2644865064.00000217196B0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1789701258.000001C5CD236000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000000.2010019478.0000021719512000.00000002.00000001.01000000.0000001A.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.1970238618.000002696E9CD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA0FC1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.1955362018.000001BE62C63000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000002.1843416546.00000000045F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1C55000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.1969655757.0000026900073000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1C21000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1789701258.000001C5CD24C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2179995487.000002E94EAA0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.1954314035.000001BE6236E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2089827549.000002332A610000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2279102001.0000020AB9720000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2184094049.000002E94F68C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2179995487.000002E94EADB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2184094049.000002E94F651000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1788731094.000001C5CB520000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1BD8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1C05000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2181419382.000002E94ED90000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1DC6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2972325371.0000016BE9E74000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2281496750.0000020AB9B20000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA1044000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2267142526.0000020AA078E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1788731094.000001C5CB526000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA12FA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA159A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000024.00000002.2614681807.00000000005B0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000003.1679439512.0000000004815000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2184094049.000002E94F523000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2267142526.0000020AA0804000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2974355709.0000016BEA2A2000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD16B3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2648816776.0000021719F41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2644540988.0000021719670000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1789701258.000001C5CD0D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2974355709.0000016BEA295000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1C3A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2935401771.0000016BD0D96000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1789701258.000001C5CD159000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2978322929.0000016BEA6E0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2938112807.0000016BD0FC0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1788731094.000001C5CB5B0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000024.00000002.2618143412.0000000000620000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1789701258.000001C5CD15C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000003.1691787592.00000000047CC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2267142526.0000020AA0750000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2972325371.0000016BE9E4D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2090008634.000002332A8A0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1F78000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2184094049.000002E94F64C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1788731094.000001C5CB562000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD21EB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.1732615847.00000000049A4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2974355709.0000016BEA2CB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2648816776.0000021719FB8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.1955362018.000001BE62BE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1793099468.000001C5E5CB8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2184094049.000002E94F491000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2940646679.0000016BD1D78000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2267142526.0000020AA082C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2184094049.000002E94F6BF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2935401771.0000016BD0D10000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1789701258.000001C5CD199000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.1732615847.0000000004901000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA14F3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2270306119.0000020AA1380000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2648816776.000002171A14A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.1969655757.0000026900001000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2184094049.000002E94F72A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 2256, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 5780, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 2084, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 2640, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 6200, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 3320, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 2916, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 2932, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 1852, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 980, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: cmd.exe PID: 3632, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: cscript.exe PID: 6768, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageSTRemote.exe PID: 1016, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: SplashtopStreamer.exe PID: 7384, type: MEMORYSTR |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.InstallLog, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF6260B0A6EE189872.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFF7EC8F46D19662E2.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIF4AD.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.CommonLib.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackage.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Config.Msi\44c50b.rbs, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF8B9C4281082EB5A9.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\UserDetections.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\AgentPackageProgramManagement.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF8F3A4106A89D3FAA.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFE942440AACDF3AD6.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF8C6157FE5230C8C7.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF98EF70557B828906.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\Microsoft_.NET_Runtime_-_6.0.35_(x64)_20241030183126_000_dotnet_runtime_6.0.35_win_x64.msi.log, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\AgentPackageUpgradeAgent.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF80F0F0EF5EAF0872.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFBAFD6533B3289355.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF91BDF3C96D5F451B.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\Microsoft_.NET_Runtime_-_6.0.35_(x64)_20241030183126_002_dotnet_host_6.0.35_win_x64.msi.log, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIDCAB.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF070AB763D94BC4D6.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\Microsoft_.NET_Runtime_-_6.0.35_(x64)_20241030183126_001_dotnet_hostfxr_6.0.35_win_x64.msi.log, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\AgentPackageADRemote.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\AgentPackageInternalPoller.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFE999D03EF0B2A4AD.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingPackageExtensions.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIDEDF.tmp, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF18D9F86597CA5126.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIC672.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF1972A83F22094FA6.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFECDCDF0BA996B022.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\RestartReminder.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF1D98EA98A0F27BD7.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF6770E5F65DEE8E27.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF8959754CB5C77D85.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\inprogressinstallinfo.ipi, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF98A3B0A404DB694E.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIC961.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF45939A071886D6FE.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF48BCAB6E3000FF9C.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF4BDFDDF68F93C3AD.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\System32\InstallUtil.InstallLog, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF38B1B8C320DF517A.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\AgentPackageTicketing.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\AgentPackageRuntimeInstaller.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\AgentPackageSystemTools.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF6B3BD24D01329A5D.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe, type: DROPPED |