Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\.version | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.runtimeconfig.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.deps.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.SecureString.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.ServicePoint.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Uri.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.CoreLib.dll | Jump to behavior |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCEA3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEAGENTINFORMATION/37.9/AGENTPACKAGEAGENTINFORMATI |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A4068EC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEHEARTBEAT/17.14/AGENTPACKAGEHEARTBEAT.ZIP |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEMONITORING/37.8/AGENTPACKAGEMONITORING.ZIP |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGESTREMOTE/23.4/AGENTPACKAGESTREMOTE.ZIP |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC368C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://a6dc35606b2c6816e.awsglobalaccelerator.com |
Source: AteraAgent.exe, 0000000D.00000000.2117978754.000002002C612000.00000002.00000001.01000000.0000000F.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCD51000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4066D1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://acontrol.atera.com/ |
Source: rundll32.exe, 00000005.00000002.2097639567.0000000004D15000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD079000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.0000000004415000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2305286440.000001640643F000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2309283038.00000270A717F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406CD1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C76000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E80251000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E801BC000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000029.00000002.2645681526.000002320057E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://agent-api.atera.com |
Source: rundll32.exe, 00000005.00000002.2097639567.0000000004D15000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD079000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.0000000004415000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2305286440.000001640643F000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2309283038.00000270A717F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406CD1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C76000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E80251000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E801BC000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000029.00000002.2645681526.000002320057E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://atera-agent-api-eu.westeurope.cloudapp.azure.com |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, _isres_0x0409.dll.42.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58A2000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392157747.000001A41F55E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392313514.000001A41F586000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4DF000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000002.2986131563.0000000000FC5000.00000002.00000001.01000000.0000001C.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, SRUsb.exe.1.dr, SQLite.Interop.dll.14.dr, System.Memory.dll3.25.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, _isres_0x0409.dll.42.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE589C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407175000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407068000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407253000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407107000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4073A1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4071E6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A40740F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407330000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406BD7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406E9A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt( |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2155600303.0000020046F9A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58A2000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2621277446.000001CACC577000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58F0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5410000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7B4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4D9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F405000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F3BD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0I |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crtt |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4DF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F467000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392313514.000001A41F56C000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC372A000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC36A9000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000002.2986131563.0000000000FC5000.00000002.00000001.01000000.0000001C.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: AteraAgent.exe, 0000000E.00000002.2621277446.000001CACC577000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE54CE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58FE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2306434674.000001641EAFA000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2306434674.000001641EA80000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2310325673.00000270BF9A0000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2310325673.00000270BFA3C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F431000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F4C9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392313514.000001A41F586000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0 |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0 |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt8 |
Source: rundll32.exe, 00000005.00000002.2098102770.0000000007433000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cl.; |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2703185005.000002326F343000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micro |
Source: rundll32.exe, 00000011.00000002.2207553911.0000000006C73000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.microsl |
Source: AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5410000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.securetrust.com/SGCA.crl0 |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5A21000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digi |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58A2000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392157747.000001A41F55E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392313514.000001A41F586000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4DF000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000002.2986131563.0000000000FC5000.00000002.00000001.01000000.0000001C.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, SRUsb.exe.1.dr, SQLite.Interop.dll.14.dr, System.Memory.dll3.25.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, _isres_0x0409.dll.42.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0 |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi | String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0= |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E458000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2155600303.0000020046F8D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152086298.000002002E43B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152086298.000002002E416000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5A1D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE589C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3391593426.000001A41F543000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000D.00000002.2150949217.000002002C8AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl& |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2155600303.0000020046F9A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCFBC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58A2000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD3CC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD000000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2621277446.000001CACC577000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD550000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58F0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5410000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0iG |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E458000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl? |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlGiR |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlhttp://crl4.digicert.co |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4DF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F467000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392313514.000001A41F56C000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC372A000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC36A9000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000002.2986131563.0000000000FC5000.00000002.00000001.01000000.0000001C.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, SRUsb.exe.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E42E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152086298.000002002E43B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE54CE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F405000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE54CE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl) |
Source: Newtonsoft.Json.dll6.25.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crlA |
Source: AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE54CE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crlESn |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crlL |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E42E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/hu |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E42E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/lxu |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, _isres_0x0409.dll.42.dr | String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02 |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E43B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlche |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E43B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com:80/DigiCertTrustedRootG4.crl6 |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5A21000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.comh |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5A21000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.R |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E42E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/ |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5A21000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/Dig7 |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, _isres_0x0409.dll.42.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2155600303.0000020046F9A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152086298.000002002E43B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2150949217.000002002C8AE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152086298.000002002E416000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCFBC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD3CC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD000000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5A1D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD550000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE589C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407175000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407068000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407253000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407107000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4073A1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4071E6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A40740F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2155600303.0000020046F9A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58A2000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2621277446.000001CACC577000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58F0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5410000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7B4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4D9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F405000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F3BD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406E9A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl8 |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE589C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlO |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlhBM |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0= |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, _isres_0x0409.dll.42.dr | String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E43B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlrlCache |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
Source: AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4DF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F489000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab |
Source: AteraAgent.exe, 00000019.00000002.3391593426.000001A41F53D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab/ |
Source: AteraAgent.exe, 00000019.00000002.3387406970.000001A41F489000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab1H |
Source: AteraAgent.exe, 00000019.00000002.3387406970.000001A41F405000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?298a0ca |
Source: AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4D9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F405000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3932cac |
Source: AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4D9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?39e9ed7 |
Source: AteraAgent.exe, 00000019.00000002.3384273316.000001A41EFE0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8a3bcea |
Source: AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4D9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3384273316.000001A41EFE0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b5d4389 |
Source: AteraAgent.exe, 00000019.00000002.3304220634.000001A405FA6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c1ec81d |
Source: AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4D9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F405000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d7a28b7 |
Source: AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f20074c |
Source: AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f43622f |
Source: AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fc542df |
Source: AteraAgent.exe, 00000019.00000002.3391593426.000001A41F53D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cabD |
Source: AteraAgent.exe, 00000019.00000002.3387406970.000001A41F431000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cabe |
Source: AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cabn6 |
Source: AteraAgent.exe, 00000019.00000002.3387406970.000001A41F498000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?298a |
Source: AteraAgent.exe, 00000019.00000002.3387406970.000001A41F498000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f200 |
Source: AteraAgent.exe, 00000019.00000002.3387406970.000001A41F498000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f436 |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC36CE000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://d17kmd0va0f0mp.cloudfront.net |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://d25btwd9wax8gu.cloudfront.net |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000000.2277568075.0000016405902000.00000002.00000001.01000000.00000016.sdmp | String found in binary or memory: http://dl.google.com/googletalk/googletalk-setup.exe |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC36CE000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://download.splashtop.com |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://fedir.comsign.co.il/crl/ComSignCA.crl0 |
Source: Newtonsoft.Json.dll6.25.dr | String found in binary or memory: http://james.newtonking.com/projects/json |
Source: rundll32.exe, 00000011.00000002.2207553911.0000000006C73000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://microsoft.cot |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC368C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://my.splashtop.com |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: http://nlog-project.org/dummynamespace/ |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: http://nlog-project.org/ws/ |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: http://nlog-project.org/ws/3 |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: http://nlog-project.org/ws/5 |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverOneWayServer/ProcessLogMessages |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverServer/ProcessLogMessagesResponsep |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverServer/ProcessLogMessagesT |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: http://nlog-project.org/ws/T |
Source: AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE54CE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5A21000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com&yc |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E42E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/ |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152086298.000002002E3EB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2621277446.000001CACC577000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE54CE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F810000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rh |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5A21000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5881000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxX |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2155600303.0000020046F9A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCFBC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58A2000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD3CC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD000000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2621277446.000001CACC577000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD550000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58F0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5410000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58FE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2306434674.000001641EAFA000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2306434674.000001641EA80000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2310325673.00000270BF9A0000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2310325673.00000270BFA3C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F431000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F4C9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392313514.000001A41F586000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0A |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58A2000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392157747.000001A41F55E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392313514.000001A41F586000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4DF000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000002.2986131563.0000000000FC5000.00000002.00000001.01000000.0000001C.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, SRUsb.exe.1.dr, SQLite.Interop.dll.14.dr, System.Memory.dll3.25.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi | String found in binary or memory: http://ocsp.digicert.com0K |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi | String found in binary or memory: http://ocsp.digicert.com0N |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, _isres_0x0409.dll.42.dr | String found in binary or memory: http://ocsp.digicert.com0O |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3391321232.000001A41F4DF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F467000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3392313514.000001A41F56C000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC372A000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC36A9000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000002.2986131563.0000000000FC5000.00000002.00000001.01000000.0000001C.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi | String found in binary or memory: http://ocsp.digicert.com0X |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRS |
Source: AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE54CE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F810000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedRootG4.crt |
Source: AteraAgent.exe, 00000019.00000002.3393096108.000001A41F810000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedRootG4.crt; |
Source: AteraAgent.exe, 00000019.00000002.3393096108.000001A41F810000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedRootG4.crtL |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E3EB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com:80/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF |
Source: AteraAgent.exe, 0000000D.00000002.2152086298.000002002E3D0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertAssuredIDRootCA.crl: |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5A21000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3387406970.000001A41F3BD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.cr |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58FE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3384273316.000001A41F086000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crlo |
Source: AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D66000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comp: |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ocsp.thawte.com0 |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ps.atera.com |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD38C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C29000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ps.pndsn.com |
Source: xdnup.dll.1.dr | String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0 |
Source: xdnup.dll.1.dr | String found in binary or memory: http://s2.symcb.com0 |
Source: AteraAgent.exe, 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org |
Source: AteraAgent.exe, 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp, System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/ |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.Collections.GenericJ |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.IO |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.Runtime.Serialization |
Source: AteraAgent.exe, 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.ServiceProcess |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.Xml |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/SystemV |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/SystemY |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/dhttp://schemas.datacontract.org/2004/07/System.XmlRhttp://w |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: rundll32.exe, 00000005.00000002.2097639567.0000000004C51000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2097639567.0000000004CF4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCD51000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.0000000004351000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.00000000043F4000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2305286440.0000016406393000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2309283038.00000270A710F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4066D1000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E80001000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E8022B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC35A8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000029.00000002.2645681526.00000232000ED000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: xdnup.dll.1.dr | String found in binary or memory: http://sv.symcb.com/sv.crl0a |
Source: xdnup.dll.1.dr | String found in binary or memory: http://sv.symcb.com/sv.crt0 |
Source: xdnup.dll.1.dr | String found in binary or memory: http://sv.symcd.com0& |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi | String found in binary or memory: http://wixtoolset.org |
Source: rundll32.exe, 00000004.00000003.2047362835.0000000004589000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.0000000004178000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.00000000040FD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v |
Source: rundll32.exe, 00000004.00000003.2047362835.0000000004589000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.0000000004178000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.00000000040FD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/news/ |
Source: rundll32.exe, 00000004.00000003.2047362835.0000000004589000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.0000000004178000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.00000000040FD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/releases/ |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2681262296.000002326E122000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: http://www.abit.com.tw/ |
Source: AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D66000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.ancert.com/cps0 |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.certplus.com/CRL/class2.crl0 |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.certplus.com/CRL/class3.crl0 |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58F0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.certplus.com/CRL/class3TS.crl0 |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCFBC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD3CC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD000000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD550000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407175000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407068000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407253000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407107000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4073A1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4071E6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A40740F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A407330000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406BD7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406E9A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4072C3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2155600303.0000020046F9A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58A2000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2621277446.000001CACC577000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE58F0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5410000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3393096108.000001A41F7B4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS8 |
Source: AteraAgent.exe, 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.e-trust.be/CPS/QNcerts |
Source: AteraAgent.exe, 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.ecee.gov.pt/dpc0 |
Source: _isres_0x0409.dll.42.dr | String found in binary or memory: http://www.flexerasoftware.com0 |
Source: xdnup.dll.1.dr | String found in binary or memory: http://www.symauth.com/cps0( |
Source: xdnup.dll.1.dr | String found in binary or memory: http://www.symauth.com/rpa00 |
Source: AteraAgent.exe, 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.o |
Source: AteraAgent.exe, 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.oh |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E80298000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E8022B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.P |
Source: rundll32.exe, 00000005.00000002.2097639567.0000000004CF4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.aterD |
Source: rundll32.exe, 00000011.00000002.2206721581.00000000043F4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.aterDf |
Source: rundll32.exe, 00000004.00000003.2047362835.0000000004589000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2097639567.0000000004C51000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2097639567.0000000004CF4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.0000000004178000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD000000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCD51000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.0000000004351000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.00000000043F4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.00000000040FD000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2305286440.0000016406393000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2309283038.00000270A710F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C76000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406E9A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E80001000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E801F8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com |
Source: rundll32.exe, 00000004.00000003.2047362835.0000000004589000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2097639567.0000000004C51000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2097639567.0000000004CF4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.0000000004178000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.0000000004351000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.00000000043F4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.00000000040FD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/ |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E80298000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Prh |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD000000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4066D1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Pro |
Source: AgentPackageAgentInformation.exe, 00000013.00000002.2305286440.0000016406393000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2309283038.00000270A710F000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E801BC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production |
Source: rundll32.exe, 00000004.00000003.2047362835.0000000004589000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2097639567.0000000004C51000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2097639567.0000000004CF4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.0000000004178000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.0000000004351000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.00000000043F4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.00000000040FD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/ |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AcknowledgeCommands |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD000000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE01000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AgentStarting |
Source: AgentPackageAgentInformation.exe, 00000013.00000002.2305286440.0000016406393000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2309283038.00000270A710F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/CommandResult |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDD4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE68000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406DEA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4068DD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406826000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetCommands |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE01000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE68000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C76000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406E9A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetCommandsFallback |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCD51000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetEnvironmentStatus |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD000000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCD51000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406D24000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4068C4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetRecurringPackages |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406D24000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4068C4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetRecurringPackagesibe |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E8022B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/ |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E8022B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/script-based |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E80001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/script-based0 |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E80298000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/guiComm |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E80298000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E80094000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/guiCommandResult |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2526006088.0000022E801BC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/recurringCommandResult |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2645681526.00000232000ED000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/thresholds/284d9381-4813-49bb-80d4-498eba240ce4 |
Source: rundll32.exe, 00000005.00000002.2097639567.0000000004C51000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2097639567.0000000004CF4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.0000000004351000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.00000000043F4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/track-event |
Source: rundll32.exe, 00000005.00000002.2097639567.0000000004D36000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000002.2206721581.0000000004436000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/track-event; |
Source: AgentPackageAgentInformation.exe, 00000014.00000002.2309283038.00000270A710F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com0 |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406826000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.comH |
Source: AteraAgent.exe, 00000019.00000002.3393096108.000001A41F830000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet-core-applaunch? |
Source: AteraAgent.exe, 00000019.00000002.3393096108.000001A41F830000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet-core-applaunch?You |
Source: AteraAgent.exe, 00000019.00000002.3393096108.000001A41F830000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet/app-launch-failed |
Source: AteraAgent.exe, 00000019.00000002.3393096108.000001A41F830000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet/app-launch-failed&gui=trueShowing |
Source: xdnup.dll.1.dr | String found in binary or memory: https://d.symcb.com/cps0% |
Source: xdnup.dll.1.dr | String found in binary or memory: https://d.symcb.com/rpa0 |
Source: Microsoft.ApplicationInsights.dll.14.dr | String found in binary or memory: https://dc.services.visualstudio.com/api/profiles/ |
Source: Microsoft.ApplicationInsights.dll.14.dr | String found in binary or memory: https://dc.services.visualstudio.com/v2/trackOStartRunnerEvent |
Source: Microsoft.ApplicationInsights.dll.14.dr | String found in binary or memory: https://dc.services.visualstudio.com/v2/trackvhttps://dc.services.visualstudio.com/api/profiles/ |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC36B1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://download.splashtop.com |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC368C000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC36B1000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC36AD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://download.splashtop.com/csrs/Splashtop_Streamer_Win_DEPLOY_INSTALLER_v3.7.2.3.exe |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2649902217.000001CAE5632000.00000002.00000001.01000000.00000020.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2306156865.000001641E9D2000.00000002.00000001.01000000.00000019.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3068191385.000001FFDBC00000.00000002.00000001.01000000.0000002B.sdmp, Newtonsoft.Json.dll6.25.dr | String found in binary or memory: https://github.com/JamesNK/Newtonsoft.Json |
Source: System.Memory.dll3.25.dr | String found in binary or memory: https://github.com/dotnet/corefx/tree/7601f4f6225089ffb291dc7d58293c7bbf5c5d4f |
Source: System.Memory.dll3.25.dr | String found in binary or memory: https://github.com/dotnet/corefx/tree/7601f4f6225089ffb291dc7d58293c7bbf5c5d4f8 |
Source: System.IO.FileSystem.Primitives.dll.1.dr, System.IO.IsolatedStorage.dll.1.dr, System.Security.Cryptography.Cng.dll.1.dr, System.Reflection.Emit.dll.1.dr, Microsoft.Extensions.Configuration.EnvironmentVariables.dll.25.dr, System.Xml.XDocument.dll.1.dr, System.Private.DataContractSerialization.dll.1.dr, Microsoft.Extensions.Hosting.dll.25.dr, Microsoft.CSharp.dll.1.dr, System.Threading.Tasks.Dataflow.dll.1.dr, System.Reflection.Primitives.dll.1.dr, System.Data.Common.dll.1.dr, System.Runtime.Serialization.Json.dll.1.dr | String found in binary or memory: https://github.com/dotnet/runtime |
Source: Microsoft.Extensions.Hosting.dll.25.dr | String found in binary or memory: https://github.com/dotnet/runtimeu |
Source: System.Threading.Tasks.Dataflow.dll.1.dr | String found in binary or memory: https://github.com/dotnet/runtimew |
Source: AteraAgent.exe, 0000000E.00000002.2663530244.000001CAE5C62000.00000002.00000001.01000000.00000021.sdmp | String found in binary or memory: https://github.com/icsharpcode/SharpZipLib |
Source: System.Data.Common.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1187 |
Source: Microsoft.Extensions.Hosting.dll.25.dr, Microsoft.CSharp.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1416. |
Source: Microsoft.CSharp.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1906. |
Source: System.Data.Common.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1981 |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC35A8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://my.splashtop.com |
Source: AgentPackageSTRemote.exe, 00000021.00000000.2346112954.000001FFC2A22000.00000002.00000001.01000000.0000001A.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC35A8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://my.splashtop.com/csrs/win |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2701107337.000002326E4E8000.00000002.00000001.01000000.00000028.sdmp, AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: https://nlog-project.org/ |
Source: AteraAgent.exe, 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000029.00000000.2571286581.000002326CFF2000.00000002.00000001.01000000.0000001D.sdmp | String found in binary or memory: https://packagesstore.blob.core.windows.net/installers/BitDefender/rmm.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCEA3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD2D3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/a |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD2D3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/ag |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCEA3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageA |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAg |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAge |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAgentI |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD2D3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE58000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageMonitoring/0.40/AgentPackageMonitoring.z |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDCC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageSTRemote/2.3/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageSTRemote/2.3/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Age |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.Availability/0.16/Agent.Package.Availability.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE43000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.IotPoc/0.2/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageADRemote/6.0/AgentPackageADRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageAgentInformation/37.9/AgentPackageAgentInformation |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageHeartbeat/17.11/AgentPackageHeartbeat.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageInternalPoller/13.0/AgentPackageInternalPoller.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMarketplace/1.6/AgentPackageMarketplace.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD2D3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE58000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD2D3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMonitoring/37.8/AgentPackageMonitoring.ziph |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE43000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageNetworkDiscovery/13.0/AgentPackageNetworkDiscovery |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageOsUpdates/20.1/AgentPackageOsUpdates.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageProgramManagement/26.0/AgentPackageProgramManageme |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE43000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageRuntimeInstaller/1.5/AgentPackageRuntimeInstaller. |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDCC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSTRemote/23.4/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSystemTools/27.6/AgentPackageSystemTools.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE43000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageTaskScheduler/13.0/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageTicketing/13.0/AgentPackageTicketing.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageUpgradeAgent/27.1/AgentPackageUpgradeAgent.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageWindowsUpdate/24.6/AgentPackageWindowsUpdate.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Availability/0.16/Agent.Package.Availability.z |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE43000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.IotPoc/0.2/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageADRemote/6.0/AgentPackageADRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageAgentInformation/37.9/AgentPackageAgentInformati |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageHeartbeat/17.14/AgentPackageHeartbeat.zip |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406733000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageHeartbeat/17.14/AgentPackageHeartbeat.zip?wr2NXt |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageInternalPoller/23.8/AgentPackageInternalPoller.z |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMarketplace/1.6/AgentPackageMarketplace.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip?wr2NX |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD2D3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.ziph |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE43000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageNetworkDiscovery/23.9/AgentPackageNetworkDiscove |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageOsUpdates/20.1/AgentPackageOsUpdates.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageProgramManagement/26.0/AgentPackageProgramManage |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageRuntimeInstaller/1.6/AgentPackageRuntimeInstalle |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDCC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406D24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip?wr2NXtXW8 |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSystemTools/27.6/AgentPackageSystemTools.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE43000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTaskScheduler/17.2/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTicketing/30.1/AgentPackageTicketing.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageUpgradeAgent/27.2/AgentPackageUpgradeAgent.zip |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageUpgradeAgent/27.2/AgentPackageUpgradeAgent.zip?w |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageWindowsUpdate/24.6/AgentPackageWindowsUpdate.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.Availability/13.0/Agent.Package.Availability.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE43000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.IotPoc/13.0/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.Watchdog/13.0/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageADRemote/1.2/AgentPackageADRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageAgentInformation/22.7/AgentPackageAgentInformation |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageHeartbeat/16.9/AgentPackageHeartbeat.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageInternalPoller/15.9/AgentPackageInternalPoller.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageMarketplace/13.0/AgentPackageMarketplace.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageMonitoring/22.0/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageNetworkDiscovery/15.0/AgentPackageNetworkDiscovery |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageOsUpdates/1.0/AgentPackageOsUpdates.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageProgramManagement/15.5/AgentPackageProgramManageme |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE43000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageRuntimeInstaller/13.0/AgentPackageRuntimeInstaller |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDCC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageSTRemote/16.0/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageSystemTools/18.9/AgentPackageSystemTools.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE43000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageTaskScheduler/13.1/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageTicketing/18.9/AgentPackageTicketing.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageUpgradeAgent/22.1/AgentPackageUpgradeAgent.zip |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageWindowsUpdate/18.3/AgentPackageWindowsUpdate.zip |
Source: AgentPackageSTRemote.exe, 00000021.00000000.2346112954.000001FFC2A22000.00000002.00000001.01000000.0000001A.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3002001112.000001FFC35A8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/installers/splashtop/win/SplashtopStreamer.exe |
Source: AgentPackageSTRemote.exe, 00000021.00000000.2346112954.000001FFC2A22000.00000002.00000001.01000000.0000001A.sdmp | String found in binary or memory: https://ps.atera.com/installers/splashtop/win/SplashtopStreamer.exepUsers/Shared/Splashtop |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD2AB000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD38C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406BD7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD2AB000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD38C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C29000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406BD7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=192114e3-5df6-42ef-a33c-d34279a8ae03 |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE01000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=31a1d677-c9d4-4a12-9909-2853690ced12 |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406826000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=3893cc6d-4a0a-4fdd-811f-3e66f5592191 |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE68000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=42678abc-61f4-48eb-823c-b8a8961e392e |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCEA3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=4a499267-2a4e-4427-ac0c-7af59e530e7c |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=516a2fc0-cc38-42d6-a877-9d4205694fbe |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A4067B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=6617a6ca-d67e-4c26-8a11-3f6180cb961f |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406E9A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=7c457aa6-9fb1-4959-bd14-3bec50b52e8b |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=972928ec-eb06-4ba7-931c-fcf4ef523213 |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD38C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=9e1765fc-ae69-4036-8b73-fbd8fe29834a |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=f05188ee-e7bb-4c94-90cc-362e7f6af776 |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/presence/sub_key/sub-c-a02ceca8 |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/presence/sub_key/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/channel/284d9381 |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406826000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscrib |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A406826000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/su |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/284d9381-4813-49bb-80d4 |
Source: AteraAgent.exe, 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v22 |
Source: AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCE01000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com2 |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2696122756.000002326E3A2000.00000002.00000001.01000000.00000027.sdmp | String found in binary or memory: https://system.data.sqlite.org/ |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2697541402.000002326E404000.00000002.00000001.01000000.00000027.sdmp | String found in binary or memory: https://system.data.sqlite.org/X |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2696122756.000002326E3A2000.00000002.00000001.01000000.00000027.sdmp | String found in binary or memory: https://urn.to/r/sds_see |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi, _isres_0x0409.dll.42.dr | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.newtonsoft.com/json |
Source: Newtonsoft.Json.dll6.25.dr | String found in binary or memory: https://www.newtonsoft.com/jsonschema |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2701107337.000002326E4E8000.00000002.00000001.01000000.00000028.sdmp, AgentPackageMonitoring.exe, 00000029.00000002.2698593851.000002326E412000.00000002.00000001.01000000.00000028.sdmp | String found in binary or memory: https://www.nuget.org/packages/NLog.Web.AspNetCore |
Source: rundll32.exe, 00000004.00000003.2047362835.00000000045BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2059698544.00000000048D1000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2099947197.00000000041A9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2649902217.000001CAE5632000.00000002.00000001.01000000.00000020.sdmp, AteraAgent.exe, 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000011.00000003.2160292802.000000000412E000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2306156865.000001641E9D2000.00000002.00000001.01000000.00000019.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3068191385.000001FFDBC00000.00000002.00000001.01000000.0000002B.sdmp, Newtonsoft.Json.dll6.25.dr | String found in binary or memory: https://www.nuget.org/packages/Newtonsoft.Json.Bson |
Source: PreVerCheck.exe, 00000027.00000002.2986131563.0000000000FC5000.00000002.00000001.01000000.0000001C.sdmp, libssl-3.dll.1.dr | String found in binary or memory: https://www.openssl.org/H |
Source: AgentPackageMonitoring.exe | String found in binary or memory: https://www.sqlite.org/copyright.html |
Source: AgentPackageMonitoring.exe, 00000029.00000002.2758741872.00007FF89F484000.00000002.00000001.01000000.0000001F.sdmp, SQLite.Interop.dll.14.dr | String found in binary or memory: https://www.sqlite.org/copyright.html2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_3_04B60040 | 5_3_04B60040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_3_04B671D0 | 5_3_04B671D0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 6_3_043D50B8 | 6_3_043D50B8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 6_3_043D59A8 | 6_3_043D59A8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 6_3_043D4D68 | 6_3_043D4D68 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 6_3_043D2644 | 6_3_043D2644 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 6_3_043D2744 | 6_3_043D2744 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FF84896C922 | 13_2_00007FF84896C922 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FF848960C1D | 13_2_00007FF848960C1D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FF84896BB76 | 13_2_00007FF84896BB76 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF84896C920 | 14_2_00007FF84896C920 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF848950D42 | 14_2_00007FF848950D42 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF84896C1F5 | 14_2_00007FF84896C1F5 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF84895C229 | 14_2_00007FF84895C229 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF848959AF2 | 14_2_00007FF848959AF2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF848961CF0 | 14_2_00007FF848961CF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF84895C540 | 14_2_00007FF84895C540 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF848B66950 | 14_2_00007FF848B66950 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF848B6E605 | 14_2_00007FF848B6E605 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF848B70ED3 | 14_2_00007FF848B70ED3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF848B70EA6 | 14_2_00007FF848B70EA6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FF848B70FF2 | 14_2_00007FF848B70FF2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_3_042857B8 | 17_3_042857B8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_3_04285850 | 17_3_04285850 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_3_066B0040 | 17_3_066B0040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_3_066B1350 | 17_3_066B1350 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_3_066B71D0 | 17_3_066B71D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FF84897FA94 | 19_2_00007FF84897FA94 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FF84899047D | 19_2_00007FF84899047D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FF848978682 | 19_2_00007FF848978682 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FF8489778D6 | 19_2_00007FF8489778D6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FF84898100A | 19_2_00007FF84898100A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FF8489712FA | 19_2_00007FF8489712FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FF84897BDB0 | 19_2_00007FF84897BDB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FF8489810C0 | 19_2_00007FF8489810C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FF84895FA94 | 20_2_00007FF84895FA94 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FF84897047D | 20_2_00007FF84897047D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FF848958682 | 20_2_00007FF848958682 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FF84896108C | 20_2_00007FF84896108C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FF8489578D6 | 20_2_00007FF8489578D6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FF848951828 | 20_2_00007FF848951828 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FF8489512FB | 20_2_00007FF8489512FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FF84895BDB0 | 20_2_00007FF84895BDB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FF8489610C0 | 20_2_00007FF8489610C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 23_2_00007FF8489512FB | 23_2_00007FF8489512FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FF848951DCC | 25_2_00007FF848951DCC |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FF848940D42 | 25_2_00007FF848940D42 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FF848963F50 | 25_2_00007FF848963F50 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FF848951A8A | 25_2_00007FF848951A8A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FF848951AB8 | 25_2_00007FF848951AB8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FF848959446 | 25_2_00007FF848959446 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FF848B66710 | 25_2_00007FF848B66710 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FF848B5F615 | 25_2_00007FF848B5F615 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FF848988956 | 28_2_00007FF848988956 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FF8489812FB | 28_2_00007FF8489812FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FF84898C47F | 28_2_00007FF84898C47F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FF848989702 | 28_2_00007FF848989702 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FF848995B31 | 28_2_00007FF848995B31 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FF848980730 | 28_2_00007FF848980730 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF8489719B0 | 33_2_00007FF8489719B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF8489652FA | 33_2_00007FF8489652FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF848968476 | 33_2_00007FF848968476 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF8489615FD | 33_2_00007FF8489615FD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF8489515FA | 33_2_00007FF8489515FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF848966F59 | 33_2_00007FF848966F59 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF8489511F2 | 33_2_00007FF8489511F2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF84896F1D3 | 33_2_00007FF84896F1D3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF84896F120 | 33_2_00007FF84896F120 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF848971AAB | 33_2_00007FF848971AAB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF848971A78 | 33_2_00007FF848971A78 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF848971A80 | 33_2_00007FF848971A80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF8489512DF | 33_2_00007FF8489512DF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF8489513F3 | 33_2_00007FF8489513F3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF848950ED3 | 33_2_00007FF848950ED3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF8489506D3 | 33_2_00007FF8489506D3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF848950740 | 33_2_00007FF848950740 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF84896F0C2 | 33_2_00007FF84896F0C2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FF848950838 | 33_2_00007FF848950838 |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_0041703C | 38_2_0041703C |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_0041B379 | 38_2_0041B379 |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_0041D31E | 38_2_0041D31E |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_00416387 | 38_2_00416387 |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_0041745C | 38_2_0041745C |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_0041043B | 38_2_0041043B |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_004254EF | 38_2_004254EF |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_0042666F | 38_2_0042666F |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_0041685C | 38_2_0041685C |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_00425A33 | 38_2_00425A33 |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_00427C42 | 38_2_00427C42 |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_00416C30 | 38_2_00416C30 |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Code function: 38_2_00425F77 | 38_2_00425F77 |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Code function: 39_2_00F977F6 | 39_2_00F977F6 |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Code function: 39_2_00F8284D | 39_2_00F8284D |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Code function: 39_2_00F91136 | 39_2_00F91136 |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Code function: 39_2_00FAFA75 | 39_2_00FAFA75 |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Code function: 39_2_00F9C263 | 39_2_00F9C263 |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Code function: 39_2_00F9E240 | 39_2_00F9E240 |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Code function: 39_2_00F82596 | 39_2_00F82596 |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Code function: 39_2_00FA2E25 | 39_2_00FA2E25 |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Code function: 39_2_00FA9F7F | 39_2_00FA9F7F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F4120E0 | 41_2_00007FF89F4120E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F36B880 | 41_2_00007FF89F36B880 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F416960 | 41_2_00007FF89F416960 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F4201E0 | 41_2_00007FF89F4201E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F37A0C0 | 41_2_00007FF89F37A0C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3840A0 | 41_2_00007FF89F3840A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2F7F30 | 41_2_00007FF89F2F7F30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F375F20 | 41_2_00007FF89F375F20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F319F30 | 41_2_00007FF89F319F30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F327E70 | 41_2_00007FF89F327E70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F313E10 | 41_2_00007FF89F313E10 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2F5E50 | 41_2_00007FF89F2F5E50 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F37FED0 | 41_2_00007FF89F37FED0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F33FEF0 | 41_2_00007FF89F33FEF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F395EA0 | 41_2_00007FF89F395EA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F387EA0 | 41_2_00007FF89F387EA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2E7EC0 | 41_2_00007FF89F2E7EC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F363EB0 | 41_2_00007FF89F363EB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3B7D20 | 41_2_00007FF89F3B7D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F423C20 | 41_2_00007FF89F423C20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3BDCC0 | 41_2_00007FF89F3BDCC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3CBCD0 | 41_2_00007FF89F3CBCD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F329CF0 | 41_2_00007FF89F329CF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F347B30 | 41_2_00007FF89F347B30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F30BBE0 | 41_2_00007FF89F30BBE0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3CDB80 | 41_2_00007FF89F3CDB80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F329BA0 | 41_2_00007FF89F329BA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F397A60 | 41_2_00007FF89F397A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F319A60 | 41_2_00007FF89F319A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F315AD0 | 41_2_00007FF89F315AD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F383AF0 | 41_2_00007FF89F383AF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F30D910 | 41_2_00007FF89F30D910 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F34B9F0 | 41_2_00007FF89F34B9F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2FD830 | 41_2_00007FF89F2FD830 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F431840 | 41_2_00007FF89F431840 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3418DA | 41_2_00007FF89F3418DA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F32D770 | 41_2_00007FF89F32D770 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F387720 | 41_2_00007FF89F387720 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F42F790 | 41_2_00007FF89F42F790 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F33F780 | 41_2_00007FF89F33F780 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2ED634 | 41_2_00007FF89F2ED634 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F34B647 | 41_2_00007FF89F34B647 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2F5640 | 41_2_00007FF89F2F5640 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F32F630 | 41_2_00007FF89F32F630 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3D56D0 | 41_2_00007FF89F3D56D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3536E0 | 41_2_00007FF89F3536E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F381690 | 41_2_00007FF89F381690 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2E955C | 41_2_00007FF89F2E955C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2E3474 | 41_2_00007FF89F2E3474 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2E74B0 | 41_2_00007FF89F2E74B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F37D350 | 41_2_00007FF89F37D350 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F37B370 | 41_2_00007FF89F37B370 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2EF340 | 41_2_00007FF89F2EF340 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3093D0 | 41_2_00007FF89F3093D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3BF3E0 | 41_2_00007FF89F3BF3E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3F3200 | 41_2_00007FF89F3F3200 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F35F220 | 41_2_00007FF89F35F220 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2ED284 | 41_2_00007FF89F2ED284 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F379170 | 41_2_00007FF89F379170 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2E11B0 | 41_2_00007FF89F2E11B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F34F1B0 | 41_2_00007FF89F34F1B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F329020 | 41_2_00007FF89F329020 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F4150F0 | 41_2_00007FF89F4150F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F37EFD0 | 41_2_00007FF89F37EFD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2F2F8C | 41_2_00007FF89F2F2F8C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F32AFB0 | 41_2_00007FF89F32AFB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F30CE70 | 41_2_00007FF89F30CE70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F340E30 | 41_2_00007FF89F340E30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2ECEA8 | 41_2_00007FF89F2ECEA8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F41CD60 | 41_2_00007FF89F41CD60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F354D00 | 41_2_00007FF89F354D00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3A8D20 | 41_2_00007FF89F3A8D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F430D30 | 41_2_00007FF89F430D30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F366D20 | 41_2_00007FF89F366D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2E4DB4 | 41_2_00007FF89F2E4DB4 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F38CC00 | 41_2_00007FF89F38CC00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F32ACD0 | 41_2_00007FF89F32ACD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F414C80 | 41_2_00007FF89F414C80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2F6CC0 | 41_2_00007FF89F2F6CC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F35CB50 | 41_2_00007FF89F35CB50 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3CAB00 | 41_2_00007FF89F3CAB00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F338B90 | 41_2_00007FF89F338B90 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F328A60 | 41_2_00007FF89F328A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3AAA70 | 41_2_00007FF89F3AAA70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2E8A3C | 41_2_00007FF89F2E8A3C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F306A80 | 41_2_00007FF89F306A80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3D6910 | 41_2_00007FF89F3D6910 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F33E990 | 41_2_00007FF89F33E990 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3A6860 | 41_2_00007FF89F3A6860 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2EE80C | 41_2_00007FF89F2EE80C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2F8860 | 41_2_00007FF89F2F8860 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3388A0 | 41_2_00007FF89F3388A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2E28C0 | 41_2_00007FF89F2E28C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2FE720 | 41_2_00007FF89F2FE720 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2F2738 | 41_2_00007FF89F2F2738 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F37A7E0 | 41_2_00007FF89F37A7E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F360600 | 41_2_00007FF89F360600 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F41C680 | 41_2_00007FF89F41C680 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2EA524 | 41_2_00007FF89F2EA524 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F364550 | 41_2_00007FF89F364550 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F330510 | 41_2_00007FF89F330510 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F39A5D0 | 41_2_00007FF89F39A5D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F4005D0 | 41_2_00007FF89F4005D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F39E590 | 41_2_00007FF89F39E590 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3C6590 | 41_2_00007FF89F3C6590 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2E85D4 | 41_2_00007FF89F2E85D4 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F41E5B0 | 41_2_00007FF89F41E5B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F2F44DC | 41_2_00007FF89F2F44DC |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3464A0 | 41_2_00007FF89F3464A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F300330 | 41_2_00007FF89F300330 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F302310 | 41_2_00007FF89F302310 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3A8310 | 41_2_00007FF89F3A8310 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F352240 | 41_2_00007FF89F352240 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F39C220 | 41_2_00007FF89F39C220 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F38A2F0 | 41_2_00007FF89F38A2F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F3822B0 | 41_2_00007FF89F3822B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF89F36C110 | 41_2_00007FF89F36C110 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF84897EEFD | 41_2_00007FF84897EEFD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF84897F78D | 41_2_00007FF84897F78D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848976D0E | 41_2_00007FF848976D0E |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848975D0F | 41_2_00007FF848975D0F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF84897BD61 | 41_2_00007FF84897BD61 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF84897D126 | 41_2_00007FF84897D126 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B931C6 | 41_2_00007FF848B931C6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B93D67 | 41_2_00007FF848B93D67 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B9370B | 41_2_00007FF848B9370B |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B9E2D8 | 41_2_00007FF848B9E2D8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B92AEB | 41_2_00007FF848B92AEB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B9130A | 41_2_00007FF848B9130A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B92408 | 41_2_00007FF848B92408 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B92558 | 41_2_00007FF848B92558 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B9ACF8 | 41_2_00007FF848B9ACF8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B9EFA8 | 41_2_00007FF848B9EFA8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848B96043 | 41_2_00007FF848B96043 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA12CF | 41_2_00007FF848CA12CF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848C932E3 | 41_2_00007FF848C932E3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA9A70 | 41_2_00007FF848CA9A70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA8BD9 | 41_2_00007FF848CA8BD9 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA3C71 | 41_2_00007FF848CA3C71 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA95DD | 41_2_00007FF848CA95DD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA4D17 | 41_2_00007FF848CA4D17 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848C9DFD1 | 41_2_00007FF848C9DFD1 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848C947A5 | 41_2_00007FF848C947A5 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA9F11 | 41_2_00007FF848CA9F11 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848C9000A | 41_2_00007FF848C9000A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA8905 | 41_2_00007FF848CA8905 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848C9012F | 41_2_00007FF848C9012F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA12FB | 41_2_00007FF848CA12FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA0D15 | 41_2_00007FF848CA0D15 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848CA8510 | 41_2_00007FF848CA8510 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848C9A61E | 41_2_00007FF848C9A61E |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D6337E | 41_2_00007FF848D6337E |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D6A1BB | 41_2_00007FF848D6A1BB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D6ECD8 | 41_2_00007FF848D6ECD8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D64EA8 | 41_2_00007FF848D64EA8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D79A43 | 41_2_00007FF848D79A43 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D755F8 | 41_2_00007FF848D755F8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D731F0 | 41_2_00007FF848D731F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D78C9B | 41_2_00007FF848D78C9B |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D75D5F | 41_2_00007FF848D75D5F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D77E68 | 41_2_00007FF848D77E68 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D76338 | 41_2_00007FF848D76338 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D77143 | 41_2_00007FF848D77143 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848D7F150 | 41_2_00007FF848D7F150 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F002D7 | 41_2_00007FF848F002D7 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F0C928 | 41_2_00007FF848F0C928 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F0A1F0 | 41_2_00007FF848F0A1F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F135F0 | 41_2_00007FF848F135F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F09C65 | 41_2_00007FF848F09C65 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F1787A | 41_2_00007FF848F1787A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F08F10 | 41_2_00007FF848F08F10 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F13F4C | 41_2_00007FF848F13F4C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F1B762 | 41_2_00007FF848F1B762 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F0783D | 41_2_00007FF848F0783D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F1BBCF | 41_2_00007FF848F1BBCF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F0A06F | 41_2_00007FF848F0A06F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 41_2_00007FF848F13F80 | 41_2_00007FF848F13F80 |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\SecuriteInfo.com.Program.RemoteAdminNET.1.4447.28224.msi" | |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 245F0EC002CAB717722C6ECEA21B7C66 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI922F.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_6263453 2 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.GenerateAgentId | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI94B1.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_6264218 6 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiStart | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIA75F.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_6268812 10 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ShouldContinueInstallation | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 1E2E8B45339738A1C08033DD0561BA90 E Global\MSI0000 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\net.exe "NET" STOP AteraAgent | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 STOP AteraAgent | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "TaskKill.exe" /f /im AteraAgent.exe | |
Source: C:\Windows\SysWOW64\taskkill.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="galbiatilag@yahoo.com.br" /CompanyId="1" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="" /AccountId="001Q300000N6lNHIAZ" /AgentId="284d9381-4813-49bb-80d4-498eba240ce4" | |
Source: unknown | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIBE96.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_6274750 32 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiEnd | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "882f16e9-6cc6-452e-9a32-9858eaee5cc2" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "87b478ef-48b2-4232-afe4-16d93c3a0dde" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "adcba5af-2fb9-4b54-8673-e032d2530dd3" agent-api.atera.com/Production 443 or8ixLi90Mf "identified" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "411f7e7f-8533-4be1-bc27-104579754f54" agent-api.atera.com/Production 443 or8ixLi90Mf "generalinfo fromGui" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cscript.exe cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "f381797e-b434-4d69-8ba0-2e18eadfef89" agent-api.atera.com/Production 443 or8ixLi90Mf "install eyJSbW1Db2RlIjoiaFpDREZQaEs3NW1KIn0=" 001Q300000N6lNHIAZ | |
Source: unknown | Process created: C:\Windows\System32\sppsvc.exe C:\Windows\system32\sppsvc.exe | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k smphost | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\Temp\SplashtopStreamer.exe "C:\Windows\TEMP\SplashtopStreamer.exe" prevercheck /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Process created: C:\Windows\Temp\unpack\PreVerCheck.exe "C:\Windows\Temp\unpack\PreVerCheck.exe" /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Process created: C:\Windows\SysWOW64\msiexec.exe msiexec /norestart /i "setup.msi" /qn /l*v "C:\Windows\TEMP\PreVer.log.txt" CA_EXTPATH=1 USERINFO="sec_opt=0,confirm_d=0,hidewindow=1" | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "9ccc455b-9d2e-475e-8aec-0d4d18e2aa7b" agent-api.atera.com/Production 443 or8ixLi90Mf "syncprofile" 001Q300000N6lNHIAZ | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding F49DF0AF5DCA5F2D6C56A64DC51D292E E Global\MSI0000 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{B39694E9-2A7A-4456-926E-4611158B0637} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{509C69C3-BB0D-4031-9446-1165B856A93C} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{C93FFE1E-17A9-41C7-8475-27BC7EF7CDE3} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{D345085D-0050-4DED-B881-873AAF513259} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{73A32404-B814-444E-B546-24E4DD5E3CD2} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{3D0CCF74-55F0-4265-A251-35FABBF51139} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{75F3F24E-BE9C-499B-A974-1A4E21DCE9EC} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{ADF329F8-F3FC-4657-854D-45BDACD50BDE} | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 245F0EC002CAB717722C6ECEA21B7C66 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 1E2E8B45339738A1C08033DD0561BA90 E Global\MSI0000 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="galbiatilag@yahoo.com.br" /CompanyId="1" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="" /AccountId="001Q300000N6lNHIAZ" /AgentId="284d9381-4813-49bb-80d4-498eba240ce4" | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding F49DF0AF5DCA5F2D6C56A64DC51D292E E Global\MSI0000 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI922F.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_6263453 2 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.GenerateAgentId | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI94B1.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_6264218 6 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiStart | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIA75F.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_6268812 10 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ShouldContinueInstallation | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIBE96.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_6274750 32 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiEnd | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\net.exe "NET" STOP AteraAgent | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "TaskKill.exe" /f /im AteraAgent.exe | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 STOP AteraAgent | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "882f16e9-6cc6-452e-9a32-9858eaee5cc2" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "87b478ef-48b2-4232-afe4-16d93c3a0dde" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "adcba5af-2fb9-4b54-8673-e032d2530dd3" agent-api.atera.com/Production 443 or8ixLi90Mf "identified" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "411f7e7f-8533-4be1-bc27-104579754f54" agent-api.atera.com/Production 443 or8ixLi90Mf "generalinfo fromGui" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "f381797e-b434-4d69-8ba0-2e18eadfef89" agent-api.atera.com/Production 443 or8ixLi90Mf "install eyJSbW1Db2RlIjoiaFpDREZQaEs3NW1KIn0=" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "9ccc455b-9d2e-475e-8aec-0d4d18e2aa7b" agent-api.atera.com/Production 443 or8ixLi90Mf "syncprofile" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\cscript.exe cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "411f7e7f-8533-4be1-bc27-104579754f54" agent-api.atera.com/Production 443 or8ixLi90Mf "generalinfo fromGui" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 284d9381-4813-49bb-80d4-498eba240ce4 "411f7e7f-8533-4be1-bc27-104579754f54" agent-api.atera.com/Production 443 or8ixLi90Mf "generalinfo fromGui" 001Q300000N6lNHIAZ | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cscript.exe cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\Temp\SplashtopStreamer.exe "C:\Windows\TEMP\SplashtopStreamer.exe" prevercheck /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Process created: C:\Windows\Temp\unpack\PreVerCheck.exe "C:\Windows\Temp\unpack\PreVerCheck.exe" /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Process created: C:\Windows\SysWOW64\msiexec.exe msiexec /norestart /i "setup.msi" /qn /l*v "C:\Windows\TEMP\PreVer.log.txt" CA_EXTPATH=1 USERINFO="sec_opt=0,confirm_d=0,hidewindow=1" | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{B39694E9-2A7A-4456-926E-4611158B0637} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{509C69C3-BB0D-4031-9446-1165B856A93C} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{C93FFE1E-17A9-41C7-8475-27BC7EF7CDE3} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{D345085D-0050-4DED-B881-873AAF513259} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{73A32404-B814-444E-B546-24E4DD5E3CD2} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{3D0CCF74-55F0-4265-A251-35FABBF51139} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{75F3F24E-BE9C-499B-A974-1A4E21DCE9EC} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe C:\Windows\TEMP\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_is63B8.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{ADF329F8-F3FC-4657-854D-45BDACD50BDE} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msihnd.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srclient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: spp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vssapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vsstrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: riched20.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: usp10.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msls31.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: edputil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wintypes.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: appresolver.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: bcp47langs.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: slc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sppc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: edputil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wintypes.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: appresolver.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: bcp47langs.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: slc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sppc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wscapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wtsapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winsta.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: devobj.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: napinsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wshbth.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: nlaapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptnet.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: smphost.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: mispace.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: sxshared.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wmiclnt.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: devobj.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wevtapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: virtdisk.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: bcd.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: fltlib.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: cscapi.dll | |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\.version | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.runtimeconfig.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.deps.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.SecureString.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.ServicePoint.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Uri.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.CoreLib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PkgHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppAnnotation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.UserSecrets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\WBAppVidRec.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x86.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI94B1.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRManager.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIB5.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\dbghelp.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.FileExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI8778.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSelfSignCertUtil.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\avutil-55.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppBrowser.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI5FF7.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\legacy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\64bits\stgamepad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomCtrl32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDetect.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVirtualDisplay.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI94B1.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileSystemGlobbing.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiCaptor.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcelt-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsbVhciCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUACCheck.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Hosting.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIBE96.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x64\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIAADE.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcrypto-3.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileProviders.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\Mirror2Extend.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\it\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI60C3.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI922F.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libx264-116.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIA75F.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\ARPPRODUCTICON.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\AgentPackageMarketplace.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stvideo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.CommandLine.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppBS.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libmp4v2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppED.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Polly.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIF931.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI620C.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Hosting.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperExx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppPB.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\PrnPort.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIFCEB.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Dapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI922F.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\qrcodelib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\fr\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIA75F.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsb.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI922F.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x64\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SROpus.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\64bits\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264Wrapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\32bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\swresample-2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI3ED8.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\RunScriptAsUser.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRApp.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\sthid.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\hidkmdf.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI94B1.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI94B1.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrlEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\setupdrv.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.EnvironmentVariables.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\32bits\stvspk.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIBE96.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI94B1.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\hidkmdf.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIBE96.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK_x86.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\64bits\stvspk.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\32bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\SetupUtil.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsbVhciCtrl32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.CoreLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIA984.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Binder.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIBE96.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppCam.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.SecureString.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppFileHound.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIA9D3.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIA75F.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI922F.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAdemWrapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Uri.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAudioChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Elevator.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\NvFBC.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIA75F.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileProviders.Physical.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PinShortCut.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x64\SRWacomUtil64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI922F.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcurl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\sthid.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdateInstall.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUtility.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeatMini.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomUtil32.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.DependencyInjection.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdwmark.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Data.SQLite.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.DependencyInjection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsb.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIA75F.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\fips.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\WdfCoInstaller01009.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIBE96.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\choco.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\stgamepad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAudioResample.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x86\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\WdfCoInstaller01009.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.ServicePoint.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE460.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\amf-vcedem-win32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stvideo.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Pubnub.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x64\SRWacomCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\OpenHardwareMonitorLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\CredentialManagement.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PkgHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.X509Certificates.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppAnnotation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\AgentPackageRuntimeInstaller.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\AgentPackageUpgradeAgent.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Interop.WUApiLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.UserSecrets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Data.SQLite.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\log4net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.Concurrent.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\WBAppVidRec.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x86.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.ThreadPool.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI94B1.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRManager.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIB5.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.FileExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI8778.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{A405BA9B-982E-4F09-B639-862B84614AF1}\ISRT.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\AgentPackageInternalPoller.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSelfSignCertUtil.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\avutil-55.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\win\lib\net6.0\System.Diagnostics.EventLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Atera.Agent.Package.Infrastructure.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppBrowser.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Diagnostics.EventLog.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{8235D436-3B90-4869-AD00-CC56622874DD}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Globalization.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{A405BA9B-982E-4F09-B639-862B84614AF1}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Algorithms.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI5FF7.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingTrayTMP.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\legacy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Options.ConfigurationExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.ServiceProcess.ServiceController.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.CompilerServices.VisualC.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\64bits\stgamepad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Console.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Process.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomCtrl32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDetect.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVirtualDisplay.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Microsoft.Win32.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI94B1.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{DE1816D1-A6E6-4114-9DB4-560737192EF9}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileSystemGlobbing.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.EventLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingNotifications.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiCaptor.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.TextWriterTraceListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Compression.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Atera.AgentCommunication.Models.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\64bits\stvad.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcelt-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsbVhciCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Hosting.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUACCheck.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Globalization.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIBE96.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Security.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.AppContext.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x64\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIAADE.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Text.RegularExpressions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcrypto-3.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileProviders.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\Mirror2Extend.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\it\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\AgentPackageHeartbeat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI60C3.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.Sinks.File.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Handles.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\pl\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XmlDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI922F.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingPackageExtensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libx264-116.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIA75F.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\netstandard.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\ARPPRODUCTICON.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Atera.Agent.Package.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\zh-Hant\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\browser\lib\net6.0\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\t2tWinFormAppBarLib.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{3FCD6A17-4757-4133-BF18-6F6FFA6F61C1}\ISRT.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\AgentPackageMarketplace.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\win\lib\net6.0\System.Diagnostics.EventLog.Messages.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Resources.Writer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.InteropServices.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\system32\SRCredentialProvider.dll (copy) | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XPath.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.EventSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stvideo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.IsolatedStorage.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.CommandLine.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppBS.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libmp4v2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Text.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppED.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Polly.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{148CAD10-AB0B-4CE9-AE4D-280717A7C8E0}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF931.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI620C.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{DE1816D1-A6E6-4114-9DB4-560737192EF9}\ISRT.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.Utils.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Hosting.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\QRCoder.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperExx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppPB.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Win32.TaskScheduler.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\PrnPort.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.Extensions.Hosting.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIFCEB.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Dapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.Console.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\CredentialManagement.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.SecureString.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI922F.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\IdleTimeFinder.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\qrcodelib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\fr\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIA75F.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsb.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{148CAD10-AB0B-4CE9-AE4D-280717A7C8E0}\ISRT.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI922F.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Polly.dll | Jump to dropped file |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Dropped PE file which has not been started: C:\Windows\Temp\unpack\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x64\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.Debug.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Tracing.dll | Jump to dropped file |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Dropped PE file which has not been started: C:\Windows\Temp\unpack\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SROpus.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\64bits\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264Wrapper.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\CommunityToolkit.WinUI.Notifications.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Microsoft.Win32.TaskScheduler.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\AgentPackageProgramManagement.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\32bits\stvad.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\de\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\swresample-2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Polly.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.Abstractions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\CredentialManagement.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.MemoryMappedFiles.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI3ED8.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\RunScriptAsUser.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRApp.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\System.Management.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.Watcher.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\sthid.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\win\lib\net6.0\System.ServiceProcess.ServiceController.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\hidkmdf.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\NLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI94B1.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI94B1.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Dropped PE file which has not been started: C:\Windows\Temp\unpack\libcrypto-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrlEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\setupdrv.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.EnvironmentVariables.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\32bits\stvspk.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\LiteDB.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIBE96.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Options.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\ru\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI94B1.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\hidkmdf.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Agent.Package.Watchdog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\AgentPackageADRemote.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ComponentModel.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIBE96.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe TID: 5996 | Thread sleep time: -30000s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1276 | Thread sleep time: -60000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 4456 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 5996 | Thread sleep count: 4630 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 5996 | Thread sleep count: 4918 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 5148 | Thread sleep time: -27670116110564310s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 5148 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 2436 | Thread sleep count: 44 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 2436 | Thread sleep time: -440000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1512 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1988 | Thread sleep time: -180000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 5148 | Thread sleep time: -44703s >= -30000s | |
Source: C:\Windows\SysWOW64\rundll32.exe TID: 6768 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 6768 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 3788 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 2608 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1496 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 2800 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7100 | Thread sleep count: 8835 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7100 | Thread sleep count: 777 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 3496 | Thread sleep count: 40 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 3496 | Thread sleep time: -36893488147419080s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 3496 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1524 | Thread sleep time: -110000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1196 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 6160 | Thread sleep time: -180000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1124 | Thread sleep count: 3668 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1124 | Thread sleep count: 4075 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -20291418481080494s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -599875s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -599762s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -599656s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -599547s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -599435s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -599325s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -599218s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -599101s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -598985s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -598875s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -598755s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -598625s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -598500s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -598385s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -598280s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -598171s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -598063s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -597952s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -597844s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -597714s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -597575s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -597422s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -596969s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -596512s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -596370s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -596218s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -596081s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -595930s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -595812s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -595703s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -595594s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -595473s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -595344s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -595233s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -595125s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -595014s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7372 | Thread sleep time: -594907s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7336 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 6408 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep count: 44 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -40582836962160988s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7244 | Thread sleep count: 6011 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -599844s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -599406s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -599238s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -599078s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -598968s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -598859s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -598690s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -598562s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -598401s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -598295s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -598185s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -598061s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -597952s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -597828s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7244 | Thread sleep count: 3755 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -597718s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -597604s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -597484s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -597373s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -597250s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -597140s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -597023s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -596828s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -596421s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -596293s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -596187s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -596062s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -595951s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -595828s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -595716s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -595594s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -595482s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -595359s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -595247s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -595124s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -595000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -594890s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -594781s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -594672s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -594562s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -594453s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -594343s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -594234s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -594071s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -593966s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -593788s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -593662s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -593531s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -593405s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -593289s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -593172s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -593061s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -592953s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -592828s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -592719s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -592609s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7240 | Thread sleep time: -592496s >= -30000s | |
Source: C:\Windows\Temp\SplashtopStreamer.exe TID: 7424 | Thread sleep time: -45000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 7752 | Thread sleep count: 2123 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 7744 | Thread sleep count: 2278 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 8004 | Thread sleep time: -14757395258967632s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 8004 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 8012 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 7716 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Windows\SysWOW64\msiexec.exe TID: 7656 | Thread sleep time: -60000s >= -30000s | |
Source: Yara match | File source: 41.2.AgentPackageMonitoring.exe.2326d3d0000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 19.2.AgentPackageAgentInformation.exe.16406240000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 41.0.AgentPackageMonitoring.exe.2326cff0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 33.0.AgentPackageSTRemote.exe.1ffc2a20000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 13.0.AteraAgent.exe.2002c610000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 19.0.AgentPackageAgentInformation.exe.16405900000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0000001C.00000002.2539707375.0000022EE967A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2526006088.0000022E80227000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACCFBC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3291300982.0000003331FF5000.00000004.00000010.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2758568487.00007FF89F479000.00000004.00000001.01000000.0000001F.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.2304677706.0000016405C30000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2539707375.0000022EE964B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000000.2346112954.000001FFC2A22000.00000002.00000001.01000000.0000001A.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A406C29000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD441000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2152086298.000002002E360000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACCDD4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000026.00000002.2996868105.00000000005A0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2541802144.0000022EEA610000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2652190289.000001CAE59A9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A406FC9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A406DEA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3384273316.000001A41F086000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2308306786.00000270A6926000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000017.00000002.2320372524.000001815E425000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2670964494.000002326D290000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2686108670.000002326E240000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2539707375.0000022EE96B8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD14A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A407175000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD211000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2999466700.000001FFC2CAE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.2304036091.0000016405B5F000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2539614990.0000022EE9610000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2670777346.000002326D0E0000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2620359444.000001CACC360000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2152681621.000002002E57C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2614097797.0000005275EF5000.00000004.00000010.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2686108670.000002326E296000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACCEA3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.2304972824.0000016406242000.00000002.00000001.01000000.00000018.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A4066D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000017.00000002.2320372524.000001815E3A9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A406D24000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.3081215271.000001FFDBDB0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000017.00000002.2321283872.000001815E610000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2308306786.00000270A68E8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.2305286440.0000016406383000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001E.00000003.2335274224.000001E7B79C0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2645681526.00000232005AC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001E.00000002.2422469028.000001E7B77F3000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A407253000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2152681621.000002002E579000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3387406970.000001A41F405000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.3001218647.000001FFC2E60000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A407107000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2652190289.000001CAE59DA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2420379591.00000291208F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3387406970.000001A41F498000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2152086298.000002002E43B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2999466700.000001FFC2CA0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2999466700.000001FFC2C60000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A40708D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000017.00000002.2320372524.000001815E3A0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2670964494.000002326D20C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2308306786.00000270A691E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2652190289.000001CAE585F000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2526006088.0000022E80001000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2652190289.000001CAE5A1D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD3CC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2152681621.000002002E5A4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2545633405.0000022EEA8A7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000017.00000002.2321344922.000001815EBF3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A4071E6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A40740F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.2304036091.0000016405B13000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2701487096.000002326EFA7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A4073A1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2308306786.00000270A68E0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2309283038.00000270A70D3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2652190289.000001CAE58FE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A40739E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A407045000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3393096108.000001A41F7E8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000000.2277568075.0000016405902000.00000002.00000001.01000000.00000016.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD000000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACCF9B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3387406970.000001A41F3B3000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACCFF7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2152681621.000002002E5AA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2155600303.0000020046FAB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001E.00000002.2422469028.000001E7B77D0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000000.2571286581.000002326CFF2000.00000002.00000001.01000000.0000001D.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000000.2117978754.000002002C612000.00000002.00000001.01000000.0000000F.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2621277446.000001CACC577000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2646185265.000001CAE5459000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3387406970.000001A41F431000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2645681526.0000023200001000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.2304036091.0000016405B1D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.2206721581.0000000004351000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3304220634.000001A405FA6000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3387406970.000001A41F3BD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001E.00000002.2422628703.000001E7B79A0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2665365606.000001CAE5D7A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2150949217.000002002C8AE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2526006088.0000022E801F8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.3002001112.000001FFC36B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A407330000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2152681621.000002002E622000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2652190289.000001CAE58B7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A40755D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD550000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2675931781.000002326D3D2000.00000002.00000001.01000000.00000022.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2526006088.0000022E80094000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2622600673.000001CACC780000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2677430520.000002326D450000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3392313514.000001A41F586000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2309283038.00000270A70C3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A407103000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A406BD7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3387406970.000001A41F447000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2156755809.00007FF8489F4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3304220634.000001A405F20000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000017.00000002.2321344922.000001815EB81000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.2305286440.0000016406311000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2526006088.0000022E80298000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3384273316.000001A41F0BC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3391593426.000001A41F532000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2621277446.000001CACC4F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A40740C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A406E9A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2150949217.000002002C820000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A407336000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000003.2047362835.0000000004589000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2539707375.0000022EE9630000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000006.00000003.2099947197.0000000004178000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2152681621.000002002E4F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2652190289.000001CAE5A21000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2309283038.00000270A7097000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2309283038.00000270A710F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD18B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2543260647.0000022EEA706000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3391321232.000001A41F4DF000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A407553000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A4070FC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2308306786.00000270A6967000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A406C10000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2526006088.0000022E801D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2999466700.000001FFC2CEC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2702158286.000002326F1B6000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.2206721581.00000000043F4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.2304036091.0000016405AD0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000017.00000002.2321344922.000001815EC03000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000005.00000002.2097639567.0000000004C51000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.2305286440.0000016406393000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2670964494.000002326D200000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACCFFD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000017.00000002.2320372524.000001815E3DE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2152681621.000002002E66C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2539707375.0000022EE966C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2150949217.000002002C861000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2526006088.0000022E80163000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000026.00000002.2995906445.0000000000500000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A406733000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A406C7D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2646185265.000001CAE54CE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.3081215271.000001FFDBE42000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2526006088.0000022E8022B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001E.00000002.2422469028.000001E7B77DC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3304220634.000001A405F5C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2670964494.000002326D252000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3384273316.000001A41EFE0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2701668806.000002326F1A5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3387406970.000001A41F467000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2309283038.00000270A7051000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2151764119.000002002CA40000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000005.00000002.2097639567.0000000004CF4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000005.00000003.2059698544.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3309556586.000001A406090000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACCDF2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3393096108.000001A41F7E0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2670964494.000002326D244000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2150949217.000002002C85E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2155426528.0000020046F40000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD394000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.3002001112.000001FFC35A8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2152681621.000002002E5A2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001C.00000002.2526006088.0000022E801BC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2645681526.00000232000ED000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2155600303.0000020046F62000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3304167134.000001A405E40000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000029.00000002.2703185005.000002326F30D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2621277446.000001CACC52C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A4072C3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A40755B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A4072C1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2308215640.00000270A68B0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000013.00000002.2304036091.0000016405BB9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A40732D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD0C9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3387406970.000001A41F3A0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A40703E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACCD51000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000003.2160292802.00000000040FD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD313000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2150949217.000002002C826000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A4068EC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2652190289.000001CAE5830000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000E.00000002.2623238825.000001CACD454000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.3002001112.000001FFC3531000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000019.00000002.3310827584.000001A40692B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.3002001112.000001FFC373B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 6052, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 5260, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 5784, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 3452, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 6192, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 6504, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 6196, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 6416, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 4760, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 2676, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 6728, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: cmd.exe PID: 6464, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: cscript.exe PID: 764, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageSTRemote.exe PID: 5612, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: SplashtopStreamer.exe PID: 7420, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageMonitoring.exe PID: 7612, type: MEMORYSTR |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackage.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFBE4583706E37C400.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\AgentPackageUpgradeAgent.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\UserDetections.dll, type: DROPPED |
Source: Yara match | File source: C:\Config.Msi\5f90c9.rbs, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\AgentPackageInternalPoller.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF8BEFF015BB8DCDE1.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.InstallLog, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\AgentPackageRuntimeInstaller.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.ModelsV3.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFA5DDE5EA76486087.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIA983.tmp, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.CommonLib.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingPackageExtensions.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF9C3DE18E0F87F25F.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\AgentPackageProgramManagement.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.CommonLib.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\AgentPackageADRemote.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSI94B1.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF952FFAD64FE600FA.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\RestartReminder.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF450DD05D30F8EE2A.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIA75F.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\AgentPackageTicketing.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIBE96.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF8F178D55DD7E0582.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\AgentPackageSystemTools.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF5DA9A21D731F521F.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\System32\InstallUtil.InstallLog, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\inprogressinstallinfo.ipi, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSI922F.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\Microsoft_.NET_Runtime_-_6.0.35_(x64)_20241107043253_000_dotnet_runtime_6.0.35_win_x64.msi.log, type: DROPPED |