Source: | Binary string: Microsoft.VisualBasic.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Xml.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.pdbMZ@ source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.ni.pdbRSDS source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Configuration.pdb`w source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Configuration.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: mscorlib.ni.pdbRSDS7^3l source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Configuration.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Xml.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Xml.ni.pdbRSDS# source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Core.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: Microsoft.VisualBasic.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Management.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: mscorlib.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Management.ni.pdbRSDSJ< source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Management.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: mscorlib.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Management.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Core.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Configuration.ni.pdbRSDScUN source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Core.pdb( source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Core.ni.pdbRSDS source: WERD106.tmp.dmp.10.dr |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: | Binary string: Microsoft.VisualBasic.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Xml.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.pdbMZ@ source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.ni.pdbRSDS source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Configuration.pdb`w source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Configuration.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: mscorlib.ni.pdbRSDS7^3l source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Configuration.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Xml.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Xml.ni.pdbRSDS# source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Core.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: Microsoft.VisualBasic.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Management.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: mscorlib.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Management.ni.pdbRSDSJ< source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Management.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: mscorlib.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Management.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Core.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Configuration.ni.pdbRSDScUN source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Core.pdb( source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.ni.pdb source: WERD106.tmp.dmp.10.dr |
Source: | Binary string: System.Core.ni.pdbRSDS source: WERD106.tmp.dmp.10.dr |
Source: 2vPsGmF7E2.exe, QJ0R4nMk343z4QJrD4ylOeLWXCuI.cs | High entropy of concatenated method names: 'zwutJfCjcQaYq9ZRFD64EyulQ8p9', 'PfZhJmYvqDWw4TBP9Nt1fAFQzHHj', 'iJ3PNJbMwldh4w3GIKFZXSKmPI6k', '_4oKjOnzYnUC9aJajz5cf0oLxEk0c6lIvRVgqRI72g5lIMtjC0tI2qz9lo08Q', 'cNmBWEPBs9oaIt3XXWz8CjbzPgWq3BpDV2F4cbAF6BYKTjk6ccA3GCX7aGU7', 'uzV0CqAl1uY9SdCYeAuFxZa0DhrwsFiuvaUU7xn0TwVbloS77wFGySQspVxU', 'knzt1ikJUXi1NaKrCBEZdaLXNdpyzIijTLc4bYzRPFGJjWiuJSnRWfaV5ihI', 'BCVwV5SaN9Bu2SAZSnNeIaNNjD3Gq5LqZ4yAsU1DvWYEeukru2ANHDMUnWhD', 'e7bqskhOd6zrOjxpKFDOjA84UYClwzBMPn9YVcXxTWLQuv4jm3WS8lISxsYO', '_0nKR6blZeLmhR7V4OiyONlNF4qsk6V2Cs7otwcWvqeMGD7evyV6hRCSwvpwz' |
Source: 2vPsGmF7E2.exe, aSjXvEPyn9WQ4no6OcWveqLvTtWOV5XilS6fDjSIIPp.cs | High entropy of concatenated method names: 'Equals', 'GetHashCode', 'GetType', 'ToString', 'Create__Instance__', 'Dispose__Instance__', 'sR0ZIsEMWDdEkokcYn4PmsQd2lRV', 'IqyYBjkxGLJDG75vFNsRi1CIfhbN', 'CtouWOBi9HTWvbuzckV02GnxU8NT', 'QgfdNae7jxBxFHNo7yJC4anoPRjR' |
Source: 2vPsGmF7E2.exe, AiNuWSI4GGACoEXz8ibcOqCp6KnZ.cs | High entropy of concatenated method names: 'oc696g3bWWRqK0NKB3ay14U4Gq8V', 'vju65yk8hgOZgYVnbYJT8HlRUxNl', 'TqNvCEOc4qHbF8XFcZAg2HOMddxF', '_8yOaSy2rMKk5qhnTxM81uU2uMcrm', 'WyPESK0g28EyjruD9XTbuZvsnwpk' |
Source: 2vPsGmF7E2.exe, OII4MuxIOXs8bBtTpxcgCMUOtZX09WUkiQ8sqmmI6ZQ.cs | High entropy of concatenated method names: 'ix73D4k23x2GSySS4Z5tUJrK7HTYk2rc5KAt5TUXwAY', 'HuKOAQ8Ra9smFQm9aVlNCHlXPfRmVHcOXkR6yZ5iWoI', '_9Zfq3mwzKXCfGSxlxydWR3h0UD3BLwJoHGrIisXDg3z', 'gqRZFrmXcm2TYqXEB6szaCM5ctPzo2ZGbZn28U7SxJg', 'OrxK11gIPOfegWjaRSSczZl2K4NeW6nWsFpVaWukQbD', 'Mv8ygDcGJ0ZQBXVhUrJMadRqV6SuZK6sM8pQcuy2pEA', '_5cBvTy4PmQ3WV3mpKAocaQ5XNJPG08iSqPhpdfaRjQS', 'xGKYOOjEApcoGuvIh4yVLZEzppVrbfzKm4YROt5e7wQ', 'wxnBH0jOVPZ3KpVgGpzjdobLRvUWLTqRVoiUZcLjnRW', '_95wsCjdoAtXnhZLQheentIQvLkGKLHnGKWGZ7QMD7oE' |
Source: 2vPsGmF7E2.exe, 4UP9xk0ffk5ExCsVe7GEekSpVUia.cs | High entropy of concatenated method names: 'gcZsP1Ob9FTiZYW5A26fUxKDnZnc', '_9C5A4QtiEImNEEgf3hsHqFNw0KGq', 'E8YCZk1ZjDW0o71DX7UyirlJjlXN', 'OkXbxW3I4Qa9RFQj8ooh8Cad9YYX', 'QqvY3YxXKI2GYaOcTipbkh6NeVrT' |
Source: 2vPsGmF7E2.exe, Z148COpZW7eomVIFwmd7cLZxNZ7z.cs | High entropy of concatenated method names: 'V2xXeoxm3yeCpdFdlzEOWDiEkiqr', 'SfXSBYYVgtcVCTn0MVzp9D7M7OZs', 'fCURN1eZDNjYBVZLsW3NVLjEqiz2', 'q8swJ59WCoP7ZkYw81KCpjaacywC', 'ZZuUr1K6y5dHdpmZbCp5jqGrAf8w', 'DEsIdCtdUXo2LHLFHYMnavmZ020J', 'LI9VMIvgal8Rshu5S1mydoUSIPsJ', 's0A1KjW0OZF6Qxe3EVhzp0loz8FJ', 'CNrcYd8RLLF4XwQmzxzbsAo7jvzn', 'V7ngOzrcXfvZDkfN6pf9Xyb9dgvD' |
Source: 2vPsGmF7E2.exe, wZFLCy4gChI2bu38pSw3OrcGeuzB.cs | High entropy of concatenated method names: '_5vj6dDOqF0p3BevxHWKF6ImQJB7z', 'irrlpnSedhnhyVQpqw1fzY7b1rVV', 'Kj3dspT2eNms6G9w02FXM27stQMK', 'FA8fhsL0i7ghOJ7zPOhgRu7SRqP2', '_7YJIzIfMaxuHRmjBgMxYDsD5RKPS', 'PKM6g5nEmCYItKGD7xE3cg3IZFQp', 'C5dXo45kApISDJgwfzXMVX52ZW4V', 'Q3dFYkbgvEDKKfLktykmNg56vhhG', 'G4KdpvyGG7JCZR7Uxg5sm2jDm6hX', 'dyeyfzPfsBKwfz5vtqmiI3lKECWa' |
Source: 2vPsGmF7E2.exe, WrqGdbr1ejCafZsJqjUyNJz1t4HlQUffZeu30F1WBzF.cs | High entropy of concatenated method names: '_5ANfkmrl6u92Q4uuOqFVLe89wonBdBSzpQ5j9HNI8de', 'zozi5ggkhubbyzgv8W8xYNpnr0ay5zHYZSRKW5I1gsm', 'cKxBVjVqpO9N5R9W9Xh3iTzDTW9KMgKifYYE12uUnVQ', 'gmqObOPDRNCZ7gflGLGrxSZgHeiae0oKNzMdaI0Y0pp', 'sg24q4jWAqBnYBUjbN8yChFLlf9xmfExsEQvTrtFFKf', 'XFEUhl8kz1cojcdAZQQey9Q6sEdCdPLVpIUFka0P3KW', 'bdrKrscnWQ6eNSgduHiTbZLyWoYdQuxRtlV6BGGVXdk', 'go654qywp2aoatRrzN5zm7EYkdBghm4Zp7Ulj9I4jp1', 'q226sO0WmQITUMg6IQmucRizLpPwlt4k2TswNjUoDwK', 'gmLA1a64lWP2dftk8nbRvK2sxvwGPAjiiVyiDwb9Win' |
Source: 2vPsGmF7E2.exe, gX0Im0RwfdnoeNfprqF3dPjVigi0.cs | High entropy of concatenated method names: 'OrfT2aFhVzOkbge0JerQ5ZRk1B92', '_7QQSNnOA3s93mRLb9e9iGteNRaiK', 'CvWFWAKRU4sZMnAt8TiPRT8PZSEC', 'hHKW8N99lFD8nFhg20N7Q5FIvedx', 'wPZcnFhSWawPgFtpFCT8U8tbRNX1', 'gbDgeea2lyLBd8O4Wr4Yy0irJIwM', 'YcqpJZfaKxo6POO1Z7yF15cxtQDo', 'l7q7UVGeeCHaoOf6Wbc1wppt5i6h', 'TsllHFIr6L278vkz007uQMMO7ADa', '_789kw0XyxYukoHqmjObMyjt5oHt0' |
Source: 2vPsGmF7E2.exe, FaoxczXjsOizcqlPcTtvaiLWBVeul6KgcqOp4pZPwAV.cs | High entropy of concatenated method names: '_2NfBQ4MOkumn5JsDAWDo5J5CNQXDoBe60Sjn49WmEB0', 'PmzDoyOg632u0saE128kC6c0EjHCMyRrlhgbhKruYo9', 'WgxxTEqasKa15WHrm4RbVr65OsB5NLv4c2sp2m0dGAp', 'WnergWgQeAdpW48HnBgT0m14hanRa3LWRmjqDhf9IHI', 'FdOYyLQf9607tsnHuy0N2X2GMLCcUDlfRjIXttVAOvA', '_7Tzb6NFBRBx3GUPhbzzcZI15vGs2GG6fhVk3jKSSMdi', '_8sftEjrtHiw0DsaRLmJK1sJXR5J5DLTmYti8xSi6cJL', 'kEZcAxvOtXBuMRbhxDGvKJSGMbIYDFxaNHEB7MKnsD2', 'nCxW0voH87EkFSihkmrUlnEHvrl561GHrcU4f9Gd4zw', 'XWbLMVSKAI7vvQhWRvhu8iTHvFqpohVPJrHPlR57FYu' |
Source: 2vPsGmF7E2.exe, zFxJfrJrPYaC3OU29FuMprE18ohQ.cs | High entropy of concatenated method names: 'hPB6j1WFauPZwEBxnOgHJcAls5Iz', 'ZnrmJPtZLF5O6F2kSdyDdK04HJ0E', 'beDUx8re9l7NG2ZPGSwJwvQ5AT6S', '_4nio0Gcbwe5KPC8YqLlVyfpdL6rv', '_02TeP4ALdyKiWA7V2OIij3YDBnd5', 'AOQDGyOdKDYdMBWPQlCxefkQIFzt', 'BVcd4GMbIlC6noI2ZmfsfQQyDk9a', 'FRYUq9Z8wRSagY1OKXuouQdfXnn4', 'i7Rhd8EFOdsTdZnVuNyFEVR4kpKS', 'S32l2jTax1OBysuOgP3NUQ8qoXDg' |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2vPsGmF7E2.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: Amcache.hve.10.dr | Binary or memory string: VMware |
Source: Amcache.hve.10.dr | Binary or memory string: VMware Virtual USB Mouse |
Source: Amcache.hve.10.dr | Binary or memory string: vmci.syshbin |
Source: Amcache.hve.10.dr | Binary or memory string: VMware, Inc. |
Source: Amcache.hve.10.dr | Binary or memory string: VMware20,1hbin@ |
Source: Amcache.hve.10.dr | Binary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563 |
Source: Amcache.hve.10.dr | Binary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Amcache.hve.10.dr | Binary or memory string: .Z$c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.10.dr | Binary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.10.dr | Binary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev |
Source: Amcache.hve.10.dr | Binary or memory string: c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.10.dr | Binary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Amcache.hve.10.dr | Binary or memory string: vmci.sys |
Source: Amcache.hve.10.dr | Binary or memory string: vmci.syshbin` |
Source: 2vPsGmF7E2.exe | Binary or memory string: vmware |
Source: Amcache.hve.10.dr | Binary or memory string: \driver\vmci,\driver\pci |
Source: Amcache.hve.10.dr | Binary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: 2vPsGmF7E2.exe, 00000000.00000002.1569117563.000000001B973000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAWne%SystemRoot%\system32\mswsock.dll, processorArchitecture=MSIL"/> |
Source: Amcache.hve.10.dr | Binary or memory string: VMware20,1 |
Source: Amcache.hve.10.dr | Binary or memory string: Microsoft Hyper-V Generation Counter |
Source: Amcache.hve.10.dr | Binary or memory string: NECVMWar VMware SATA CD00 |
Source: Amcache.hve.10.dr | Binary or memory string: VMware Virtual disk SCSI Disk Device |
Source: Amcache.hve.10.dr | Binary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom |
Source: Amcache.hve.10.dr | Binary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk |
Source: Amcache.hve.10.dr | Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver |
Source: Amcache.hve.10.dr | Binary or memory string: VMware PCI VMCI Bus Device |
Source: Amcache.hve.10.dr | Binary or memory string: VMware VMCI Bus Device |
Source: Amcache.hve.10.dr | Binary or memory string: VMware Virtual RAM |
Source: Amcache.hve.10.dr | Binary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1 |
Source: Amcache.hve.10.dr | Binary or memory string: VMware-42 27 88 19 56 cc 59 1a-97 79 fb 8c bf a1 e2 9d |
Source: Amcache.hve.10.dr | Binary or memory string: vmci.inf_amd64_68ed49469341f563 |