Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\.version | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.runtimeconfig.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.deps.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.SecureString.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.ServicePoint.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Uri.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.CoreLib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Algorithms.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\netstandard.dll | Jump to behavior |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED001A1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEAGENTINFORMATION/37.9/AGENTPACKAGEAGENTINFORMATI |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEMONITORING/37.8/AGENTPACKAGEMONITORING.ZIP |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGESTREMOTE/23.4/AGENTPACKAGESTREMOTE.ZIP |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E21000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://a6dc35606b2c6816e.awsglobalaccelerator.com |
Source: AteraAgent.exe, 0000000D.00000000.2199948262.00000136F9392000.00000002.00000001.01000000.0000000F.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00001000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B306F51000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://acontrol.atera.com/ |
Source: rundll32.exe, 00000005.00000002.2164513583.0000000004BF5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0029A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00398000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00292000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.00000000048F5000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2402335332.0000024A55C1F000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000015.00000002.2403192537.00000141D3DAF000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801CF000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801BC000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.0000025880253000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000025.00000002.2537573513.000002510057C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://agent-api.atera.com |
Source: rundll32.exe, 00000005.00000002.2164513583.0000000004BF5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0029A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00398000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00292000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.00000000048F5000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2402335332.0000024A55C1F000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000015.00000002.2403192537.00000141D3DAF000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801CF000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.0000025880253000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000025.00000002.2537573513.000002510057C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://atera-agent-api-eu.westeurope.cloudapp.azure.com |
Source: AteraAgent.exe, 00000019.00000002.3441018014.000001B31F76D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://c._ |
Source: AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB56000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCer7 |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi, _is6726.exe.43.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7A4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2739199591.000001ED79990000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3381094657.000001B3066A5000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB2F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FAFD000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3441018014.000001B31F720000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB4C000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000029.00000002.3027117110.0000000000805000.00000002.00000001.01000000.00000026.sdmp, LaudoBombeirosPDF.msi, SQLite.Interop.dll.14.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, 5b22ac.msi.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi, _is6726.exe.43.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 |
Source: AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002F5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002E8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0062B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307461000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307963000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307719000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3078EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3074DA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307895000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3075C0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30754D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307632000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30737B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3076A5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3079D4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3072FC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt |
Source: AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB08B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2272602696.00000136800C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A690000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5F8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2739199591.000001ED799C6000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A681000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB36000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445366599.000001B31FACE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB2F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FAFD000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3441018014.000001B31F76D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3441018014.000001B31F720000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crtG |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB08B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB36000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB2F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FAFD000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB56000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197EBF000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E3F000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000029.00000002.3027117110.0000000000805000.00000002.00000001.01000000.00000026.sdmp, LaudoBombeirosPDF.msi, SQLite.Interop.dll.14.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A69D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5F8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7A4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A681000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2739199591.000001ED79990000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2404146474.0000024A6E30E000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2404146474.0000024A6E260000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000015.00000002.2407972711.00000141EC3C6000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3441018014.000001B31F7B7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB36000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0 |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, 5b22ac.msi.2.dr | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0 |
Source: AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5F8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com:80/DigiCertTrustedRootG4.crt |
Source: AteraAgent.exe, 0000000E.00000002.2732468944.000001ED79213000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cps.chambersign.org/cps/chambersignroot.html0 |
Source: AteraAgent.exe, 0000000E.00000002.2732468944.000001ED79213000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.chambersign.org/chambersignroot.crl0 |
Source: mv2.sys1.2.dr | String found in binary or memory: http://crl.globalsign.net/ObjectSign.crl0 |
Source: mv2.sys1.2.dr | String found in binary or memory: http://crl.globalsign.net/Root.crl0 |
Source: mv2.sys1.2.dr | String found in binary or memory: http://crl.globalsign.net/primobject.crl0 |
Source: rundll32.exe, 00000005.00000002.2165086500.0000000007460000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micro |
Source: stvideo.dll.2.dr, hidkmdf.sys.2.dr, XDColMan.dll.2.dr, stgamepad.sys0.2.dr | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB1E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/ |
Source: AteraAgent.exe, 0000000D.00000002.2276134815.00000136FB0F7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/61 |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7A4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2739199591.000001ED79990000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3381094657.000001B3066A5000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB2F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FAFD000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3441018014.000001B31F720000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB4C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB56000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000029.00000002.3027117110.0000000000805000.00000002.00000001.01000000.00000026.sdmp, LaudoBombeirosPDF.msi | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi, _is6726.exe.43.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, 5b22ac.msi.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0 |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi | String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0= |
Source: AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA |
Source: AteraAgent.exe, 0000000D.00000002.2276134815.00000136FB0F7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB08B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2272602696.00000136800C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002F5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A690000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002E8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5F8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2739199591.000001ED799C6000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A681000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0062B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB36000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: AteraAgent.exe, 00000019.00000002.3441018014.000001B31F7B7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlhttp://crl4.digicert.co |
Source: AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CAl |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB08B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB36000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB2F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FAFD000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB56000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197EBF000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E3F000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000029.00000002.3027117110.0000000000805000.00000002.00000001.01000000.00000026.sdmp, LaudoBombeirosPDF.msi, SQLite.Interop.dll.14.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: AteraAgent.exe, 00000019.00000002.3444081727.000001B31FA47000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: Serilog.Extensions.Hosting.dll.25.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, 5b22ac.msi.2.dr | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi, _is6726.exe.43.dr | String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02 |
Source: AteraAgent.exe, 0000000D.00000002.2276134815.00000136FB12B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digi |
Source: AteraAgent.exe, 0000000D.00000002.2276134815.00000136FB0F7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/ |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi, _is6726.exe.43.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB1E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTru |
Source: AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB56000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA40 |
Source: AteraAgent.exe, 0000000D.00000002.2274696750.00000136F96D7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2276134815.00000136FB0F7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002F5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002E8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0062B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307461000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307963000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307719000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3078EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3074DA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307895000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3075C0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30754D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307632000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30737B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3076A5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3079D4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3072FC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000D.00000002.2276134815.00000136FB12B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl/ |
Source: AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB08B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2272602696.00000136800C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A690000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5F8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2739199591.000001ED799C6000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A681000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB36000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445366599.000001B31FACE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB2F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FAFD000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3441018014.000001B31F76D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3441018014.000001B31F720000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlA |
Source: AteraAgent.exe, 0000000D.00000002.2276134815.00000136FB12B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlH |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, 5b22ac.msi.2.dr | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0= |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi, _is6726.exe.43.dr | String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2276134815.00000136FB12B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A69D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en |
Source: AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5F8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.caber |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E63000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://d17kmd0va0f0mp.cloudfront.net |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://d25btwd9wax8gu.cloudfront.net |
Source: AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A69D000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000000.2362001539.0000024A55052000.00000002.00000001.01000000.00000016.sdmp, AgentPackageAgentInformation.exe.14.dr | String found in binary or memory: http://dl.google.com/googletalk/googletalk-setup.exe |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E63000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://download.splashtop.com |
Source: Newtonsoft.Json.dll1.14.dr | String found in binary or memory: http://james.newtonking.com/projects/json |
Source: rundll32.exe, 00000006.00000002.2169275402.000000000333D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://msdn.micros |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E21000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://my.splashtop.com |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/dummynamespace/ |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/ |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/3 |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/5 |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverOneWayServer/ProcessLogMessages |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverServer/ProcessLogMessagesResponsep |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverServer/ProcessLogMessagesT |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/T |
Source: AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB1E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.c |
Source: AteraAgent.exe, 0000000D.00000002.2276134815.00000136FB12B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB071000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3444081727.000001B31FA54000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rh |
Source: AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB071000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxL |
Source: AteraAgent.exe, 00000019.00000002.3441018014.000001B31F720000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3444081727.000001B31FA54000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxX |
Source: AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB08B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2272602696.00000136800C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002F5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A690000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002E8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5F8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2739199591.000001ED799C6000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A681000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0062B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB36000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5F8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7A4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A681000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2739199591.000001ED79990000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2404146474.0000024A6E30E000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2404146474.0000024A6E260000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000015.00000002.2407972711.00000141EC3C6000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3441018014.000001B31F7B7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB36000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0A |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7A4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2739199591.000001ED79990000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3381094657.000001B3066A5000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB2F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FAFD000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3441018014.000001B31F720000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB4C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB56000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000029.00000002.3027117110.0000000000805000.00000002.00000001.01000000.00000026.sdmp, LaudoBombeirosPDF.msi | String found in binary or memory: http://ocsp.digicert.com0C |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi | String found in binary or memory: http://ocsp.digicert.com0K |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi | String found in binary or memory: http://ocsp.digicert.com0N |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi, 5b22ac.msi.2.dr, _is6726.exe.43.dr | String found in binary or memory: http://ocsp.digicert.com0O |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB08B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB36000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB2F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FAFD000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197EBF000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E3F000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000029.00000002.3027117110.0000000000805000.00000002.00000001.01000000.00000026.sdmp, LaudoBombeirosPDF.msi, SQLite.Interop.dll.14.dr, 5b22ac.msi.2.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: AteraAgent.exe, 00000019.00000002.3444081727.000001B31FA62000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRS |
Source: AteraAgent.exe, 00000019.00000002.3444081727.000001B31FA54000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedRootG4.crt |
Source: AteraAgent.exe, 00000019.00000002.3444081727.000001B31FA54000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedRootG4.crt1 |
Source: AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedRootG4.crtF |
Source: AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB08B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertAssuredIDRootCA.crl |
Source: AteraAgent.exe, 00000019.00000002.3444081727.000001B31FA54000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.cr |
Source: AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB08B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3441018014.000001B31F7D1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: AteraAgent.exe, 0000000E.00000002.2739199591.000001ED799EE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crlD- |
Source: AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.suscerte.gob.ve0 |
Source: stvideo.dll.2.dr, hidkmdf.sys.2.dr, XDColMan.dll.2.dr, stgamepad.sys0.2.dr | String found in binary or memory: http://ocsp.thawte.com0 |
Source: AteraAgent.exe, 0000000E.00000002.2748450467.000001ED7AA89000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://policy.camerfirma.com0 |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ps.atera.com |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0029A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ps.pndsn.com |
Source: stvideo.dll.2.dr, XDColMan.dll.2.dr | String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0 |
Source: stvideo.dll.2.dr, XDColMan.dll.2.dr | String found in binary or memory: http://s2.symcb.com0 |
Source: AteraAgent.exe, 0000000D.00000002.2272602696.00000136800C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org |
Source: AteraAgent.exe, 0000000D.00000002.2272602696.00000136800C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org/2004/07/ |
Source: AteraAgent.exe, 0000000D.00000002.2272602696.00000136800C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.ServiceProcess |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: System.Security.Principal.Windows.dll.2.dr | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid |
Source: rundll32.exe, 00000005.00000002.2164513583.0000000004BD4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2164513583.0000000004B31000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00001000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.0000000004831000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.00000000048D4000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2402335332.0000024A55B73000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000015.00000002.2403192537.00000141D3D3F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B306F51000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.000002588022B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197D38000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000025.00000002.2537573513.00000251000ED000.00000004.00000800.00020000.00000000.sdmp, System.Security.Principal.Windows.dll.2.dr | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.0000025880001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name0 |
Source: XDColMan.dll.2.dr | String found in binary or memory: http://sv.symcb.com/sv.crl0a |
Source: stvideo.dll.2.dr | String found in binary or memory: http://sv.symcb.com/sv.crl0f |
Source: stvideo.dll.2.dr, XDColMan.dll.2.dr | String found in binary or memory: http://sv.symcb.com/sv.crt0 |
Source: stvideo.dll.2.dr, XDColMan.dll.2.dr | String found in binary or memory: http://sv.symcd.com0& |
Source: stvideo.dll.2.dr, hidkmdf.sys.2.dr, XDColMan.dll.2.dr, stgamepad.sys0.2.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: stvideo.dll.2.dr, hidkmdf.sys.2.dr, XDColMan.dll.2.dr, stgamepad.sys0.2.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: stvideo.dll.2.dr, hidkmdf.sys.2.dr, XDColMan.dll.2.dr, stgamepad.sys0.2.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi | String found in binary or memory: http://wixtoolset.org |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DC3000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000486C000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D56000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004524000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DC3000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000486C000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D56000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004524000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/news/ |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DC3000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000486C000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D56000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004524000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/releases/ |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2570549513.000002517F5F2000.00000002.00000001.01000000.0000001F.sdmp | String found in binary or memory: http://www.abit.com.tw/ |
Source: AteraAgent.exe, 0000000E.00000002.2748450467.000001ED7AA89000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.acabogacia.org/doc0 |
Source: AteraAgent.exe, 0000000E.00000002.2748450467.000001ED7AA89000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.acabogacia.org0 |
Source: AteraAgent.exe, 0000000E.00000002.2748450467.000001ED7AA89000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.ancert.com/cps0 |
Source: AteraAgent.exe, 0000000E.00000002.2732468944.000001ED79213000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.chambersign.org1 |
Source: AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.datev.de/zertifikat-policy-bt0 |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002F5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002E8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0062B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307461000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307963000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307719000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3078EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3074DA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307895000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3075C0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30754D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307632000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B307374000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3076A5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3079D4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3072FC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2277621490.00000136FBAEF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2275418534.00000136FB08B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2272602696.00000136800C9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A690000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5F8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED006AD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A5D4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2739199591.000001ED799C6000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2742213676.000001ED7A681000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445996918.000001B31FB36000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3445366599.000001B31FACE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: MSIF99F.tmp.2.dr, _is6726.exe.43.dr | String found in binary or memory: http://www.flexerasoftware.com0 |
Source: rundll32.exe, 00000005.00000002.2165086500.0000000007460000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.microsof. |
Source: rundll32.exe, 00000005.00000002.2165086500.0000000007460000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.microsof..m/pki/ |
Source: PreVer.log.txt.2.dr | String found in binary or memory: http://www.splashtop.com/remote |
Source: AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.suscerte.gob.ve/dpc0 |
Source: AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AAB4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.suscerte.gob.ve/lcr0# |
Source: stvideo.dll.2.dr, XDColMan.dll.2.dr | String found in binary or memory: http://www.symauth.com/cps0( |
Source: stvideo.dll.2.dr, XDColMan.dll.2.dr | String found in binary or memory: http://www.symauth.com/rpa00 |
Source: AteraAgent.exe, 0000000D.00000002.2272602696.00000136800C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.o |
Source: AteraAgent.exe, 0000000D.00000002.2272602696.00000136800C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.oh |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.000002588022B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.P |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.000002588029A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.PH |
Source: rundll32.exe, 00000005.00000002.2164513583.0000000004BD4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.aterD |
Source: rundll32.exe, 00000012.00000002.2340849722.00000000048D4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.aterDR |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DC3000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2164513583.0000000004BD4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2164513583.0000000004B31000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000486C000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D56000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00001000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00398000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00292000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004524000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.0000000004831000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.00000000048D4000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000013.00000002.2402335332.0000024A55B73000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000015.00000002.2403192537.00000141D3D3F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30707F000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.000002588022B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.0000025880001000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801BC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DC3000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2164513583.0000000004BD4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2164513583.0000000004B31000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000486C000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D56000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004524000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.0000000004831000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.00000000048D4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/ |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.000002588029A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Prh |
Source: AteraAgent.exe, 00000019.00000002.3389390881.000001B306F51000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Pro |
Source: AgentPackageAgentInformation.exe, 00000013.00000002.2402335332.0000024A55B73000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000015.00000002.2403192537.00000141D3D3F000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801BC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DC3000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2164513583.0000000004BD4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2164513583.0000000004B31000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000486C000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D56000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00292000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004524000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.0000000004831000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.00000000048D4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/ |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00292000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AcknowledgeCommands |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00398000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED000B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AgentStarting |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00400000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AgentStarting) |
Source: AgentPackageAgentInformation.exe, 00000013.00000002.2402335332.0000024A55B73000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000015.00000002.2403192537.00000141D3D3F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/CommandResult |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00084000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3071BD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetCommands |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED000B0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30707F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3071BD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetCommandsFallback |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetEnvironmentStatus |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetRecurringPackages |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.000002588022B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/ |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.000002588022B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.0000025880001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/script-based |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.000002588029A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/guiComm |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.0000025880093000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.000002588029A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/guiCommandResult |
Source: AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001C.00000002.2658062282.00000258801BC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/recurringCommandResult |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2537573513.00000251000ED000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/thresholds/b51e08a8-64b6-4fa7-a5d2-aaa39484ab8a |
Source: rundll32.exe, 00000005.00000002.2164513583.0000000004BD4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.2164513583.0000000004B31000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.0000000004831000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.00000000048D4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/track-event |
Source: rundll32.exe, 00000005.00000002.2164513583.0000000004C16000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000002.2340849722.0000000004916000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/track-event; |
Source: AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet-core-applaunch? |
Source: AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet-core-applaunch?You |
Source: System.Text.Json.dll.2.dr | String found in binary or memory: https://aka.ms/dotnet-warnings/ |
Source: AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet/app-launch-failed |
Source: AteraAgent.exe, 00000019.00000002.3447135217.000001B31FB65000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet/app-launch-failed&gui=trueShowing |
Source: stvideo.dll.2.dr, XDColMan.dll.2.dr | String found in binary or memory: https://d.symcb.com/cps0% |
Source: stvideo.dll.2.dr, XDColMan.dll.2.dr | String found in binary or memory: https://d.symcb.com/rpa0 |
Source: Microsoft.ApplicationInsights.dll.14.dr | String found in binary or memory: https://dc.services.visualstudio.com/api/profiles/ |
Source: Microsoft.ApplicationInsights.dll.14.dr | String found in binary or memory: https://dc.services.visualstudio.com/v2/trackOStartRunnerEvent |
Source: Microsoft.ApplicationInsights.dll.14.dr | String found in binary or memory: https://dc.services.visualstudio.com/v2/trackvhttps://dc.services.visualstudio.com/api/profiles/ |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E47000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://download.splashtop.com |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E21000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E43000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E47000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://download.splashtop.com/csrs/Splashtop_Streamer_Win_DEPLOY_INSTALLER_v3.7.2.3.exe |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000015.00000002.2402225096.00000141D3BB2000.00000002.00000001.01000000.00000019.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3116821083.00000181B0450000.00000002.00000001.01000000.0000002B.sdmp, AgentPackageMonitoring.exe, 00000025.00000002.2578602332.000002517F952000.00000002.00000001.01000000.00000023.sdmp, Newtonsoft.Json.dll6.25.dr, Newtonsoft.Json.dll1.14.dr | String found in binary or memory: https://github.com/JamesNK/Newtonsoft.Json |
Source: System.Memory.dll3.25.dr | String found in binary or memory: https://github.com/dotnet/corefx/tree/7601f4f6225089ffb291dc7d58293c7bbf5c5d4f |
Source: System.Memory.dll3.25.dr | String found in binary or memory: https://github.com/dotnet/corefx/tree/7601f4f6225089ffb291dc7d58293c7bbf5c5d4f8 |
Source: System.Security.Cryptography.OpenSsl.dll.2.dr, System.Security.AccessControl.dll.2.dr, System.Data.DataSetExtensions.dll.2.dr, Microsoft.Extensions.Configuration.EnvironmentVariables.dll.25.dr, Microsoft.Extensions.Hosting.dll.25.dr, System.Reflection.Primitives.dll.2.dr, System.Xml.XmlSerializer.dll.2.dr, System.Runtime.Serialization.Json.dll.2.dr, System.IO.UnmanagedMemoryStream.dll.2.dr, System.Reflection.TypeExtensions.dll.2.dr, System.Text.Json.dll.2.dr, System.Security.Principal.Windows.dll.2.dr | String found in binary or memory: https://github.com/dotnet/runtime |
Source: System.Security.Cryptography.OpenSsl.dll.2.dr, System.Reflection.TypeExtensions.dll.2.dr | String found in binary or memory: https://github.com/dotnet/runtimeBSJB |
Source: Microsoft.Extensions.Hosting.dll.25.dr | String found in binary or memory: https://github.com/dotnet/runtimeu |
Source: AteraAgent.exe, 0000000E.00000002.2747820006.000001ED7A982000.00000002.00000001.01000000.00000029.sdmp | String found in binary or memory: https://github.com/icsharpcode/SharpZipLib |
Source: Microsoft.Extensions.Hosting.dll.25.dr, System.Text.Json.dll.2.dr | String found in binary or memory: https://github.com/mono/linker/issues/1416. |
Source: Serilog.Extensions.Hosting.dll.25.dr | String found in binary or memory: https://github.com/serilog/serilog-extensions-hosting |
Source: Serilog.Extensions.Hosting.dll.25.dr | String found in binary or memory: https://github.com/serilog/serilog-extensions-hostingd |
Source: AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197E1C000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197D38000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://my.splashtop.com |
Source: AgentPackageSTRemote.exe, 00000021.00000000.2435314202.0000018197262000.00000002.00000001.01000000.0000001A.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197D38000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://my.splashtop.com/csrs/win |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp, AgentPackageMonitoring.exe, 00000025.00000002.2577600139.000002517F948000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: https://nlog-project.org/ |
Source: AteraAgent.exe, 0000000E.00000002.2748677492.000001ED7AADE000.00000004.00000020.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000025.00000000.2471842556.000002517E492000.00000002.00000001.01000000.0000001B.sdmp | String found in binary or memory: https://packagesstore.blob.core.windows.net/installers/BitDefender/rmm.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/a |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/ag |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageA |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00273000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageA6 |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00273000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageA6437 |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAg |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00400000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAge8X |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAgentI |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00080000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageMonitoring/0.40/AgentPackageMonitoring.z |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00400000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageSTRemote/2.3/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageSTRemote/2.3/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.IotPoc/0.2/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageAgentInformation/37.9/AgentPackageAgentInformation |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00080000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMonitoring/37.8/AgentPackageMonitoring.ziph |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageNetworkDiscovery/13.0/AgentPackageNetworkDiscovery |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageRuntimeInstaller/1.5/AgentPackageRuntimeInstaller. |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00400000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSTRemote/23.4/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageTaskScheduler/13.0/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Availability/0.16/Agent.Package.Availability.z |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.IotPoc/0.2/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageADRemote/6.0/AgentPackageADRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageAgentInformation/37.9/AgentPackageAgentInformati |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageHeartbeat/17.14/AgentPackageHeartbeat.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageInternalPoller/23.8/AgentPackageInternalPoller.z |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMarketplace/1.6/AgentPackageMarketplace.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00080000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip?5lbJW |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.ziph |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageNetworkDiscovery/23.9/AgentPackageNetworkDiscove |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageOsUpdates/20.1/AgentPackageOsUpdates.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageProgramManagement/26.0/AgentPackageProgramManage |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30707F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageRuntimeInstaller/1.6/AgentPackageRuntimeInstalle |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00400000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip?5lbJWdm3J |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSystemTools/27.6/AgentPackageSystemTools.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTaskScheduler/17.2/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTicketing/30.1/AgentPackageTicketing.zip |
Source: AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTicketing/30.1/AgentPackageTicketing.zip?5lbJWdm |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageUpgradeAgent/27.2/AgentPackageUpgradeAgent.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageWindowsUpdate/24.6/AgentPackageWindowsUpdate.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.IotPoc/13.0/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.Watchdog/13.0/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageAgentInformation/22.7/AgentPackageAgentInformation |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageHeartbeat/16.9 |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00080000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageMonitoring/22.0/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00058000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageRuntimeInstaller/13.0/AgentPackageRuntimeInstaller |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0041A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageSTRemote/16.0/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0007C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageTaskScheduler/13.1/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000000.2435314202.0000018197262000.00000002.00000001.01000000.0000001A.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3086547943.0000018197D38000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/installers/splashtop/win/SplashtopStreamer.exe |
Source: AteraAgent.exe, 0000000E.00000002.2747138827.000001ED7A7BB000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000000.2435314202.0000018197262000.00000002.00000001.01000000.0000001A.sdmp | String found in binary or memory: https://ps.atera.com/installers/splashtop/win/SplashtopStreamer.exepUsers/Shared/Splashtop |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED001A1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.come |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0029A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003F2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0029A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003F2000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00530000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=00a64d30-92c4-4bc1-931c-fb07dc26c3ea |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00467000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=323adb27-39ac-4a83-98d7-6a8a959de703 |
Source: AteraAgent.exe, 00000019.00000002.3389390881.000001B3071BD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=40e20ed9-b6cd-4def-a043-22a02296ebb8 |
Source: AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=5dd43e31-e0c4-429b-a1a2-f853c16a1e1f |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED003E1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=a43c154a-e264-46e0-b1be-274a658c8681 |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=b1058038-dfee-4586-9a68-a2081b432e7e |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED00112000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=c398891b-a178-4e2f-a0ac-e28e288df248 |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED0029A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=ca87155e-a756-46a3-8c73-d89c8269fd7c |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED000B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=f3ba13a5-a6ad-4254-a306-ae5097084aeb |
Source: AteraAgent.exe, 00000019.00000002.3389390881.000001B30707F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/presence/sub_key/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/channel/b51e08a8 |
Source: AteraAgent.exe, 00000019.00000002.3389390881.000001B3071BD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscrib |
Source: AteraAgent.exe, 00000019.00000002.3389390881.000001B30707F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B30700D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000019.00000002.3389390881.000001B3071BD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/b51e08a8-64b6-4fa7-a5d2 |
Source: AteraAgent.exe, 0000000E.00000002.2706500939.000001ED000B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.comtLog |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2580548392.000002517FA12000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: https://system.data.sqlite.org/ |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2580873238.000002517FA74000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: https://system.data.sqlite.org/X |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2580548392.000002517FA12000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: https://urn.to/r/sds_see |
Source: 5b22ac.msi.2.dr | String found in binary or memory: https://wixtoolset.org/ |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, LaudoBombeirosPDF.msi, _is6726.exe.43.dr | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.newtonsoft.com/json |
Source: Newtonsoft.Json.dll1.14.dr | String found in binary or memory: https://www.newtonsoft.com/jsonschema |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2575939508.000002517F872000.00000002.00000001.01000000.00000022.sdmp, AgentPackageMonitoring.exe, 00000025.00000002.2577600139.000002517F948000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: https://www.nuget.org/packages/NLog.Web.AspNetCore |
Source: rundll32.exe, 00000004.00000003.2115968207.0000000004DF4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.2128394629.000000000489D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.2167140424.0000000004D87000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED005F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000E.00000002.2706500939.000001ED002A4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000012.00000003.2283511180.0000000004555000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000015.00000002.2402225096.00000141D3BB2000.00000002.00000001.01000000.00000019.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.3116821083.00000181B0450000.00000002.00000001.01000000.0000002B.sdmp, AgentPackageMonitoring.exe, 00000025.00000002.2578602332.000002517F952000.00000002.00000001.01000000.00000023.sdmp, Newtonsoft.Json.dll6.25.dr, Newtonsoft.Json.dll1.14.dr | String found in binary or memory: https://www.nuget.org/packages/Newtonsoft.Json.Bson |
Source: PreVerCheck.exe, 00000029.00000002.3027117110.0000000000805000.00000002.00000001.01000000.00000026.sdmp | String found in binary or memory: https://www.openssl.org/H |
Source: AgentPackageMonitoring.exe | String found in binary or memory: https://www.sqlite.org/copyright.html |
Source: AgentPackageMonitoring.exe, 00000025.00000002.2637169428.00007FFD8B774000.00000002.00000001.01000000.0000001C.sdmp, SQLite.Interop.dll.14.dr | String found in binary or memory: https://www.sqlite.org/copyright.html2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_3_06F077F0 | 5_3_06F077F0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_3_06F00040 | 5_3_06F00040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 6_3_04F150B8 | 6_3_04F150B8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 6_3_04F159A8 | 6_3_04F159A8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 6_3_04F14D68 | 6_3_04F14D68 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD33FFC922 | 13_2_00007FFD33FFC922 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD33FF6058 | 13_2_00007FFD33FF6058 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD33FF986D | 13_2_00007FFD33FF986D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD33FFA094 | 13_2_00007FFD33FFA094 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD33FFBB76 | 13_2_00007FFD33FFBB76 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD33FF7FF2 | 13_2_00007FFD33FF7FF2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD340E0002 | 13_2_00007FFD340E0002 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD33FF0D42 | 14_2_00007FFD33FF0D42 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD33FFCFB8 | 14_2_00007FFD33FFCFB8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD34001CE0 | 14_2_00007FFD34001CE0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD33FFC500 | 14_2_00007FFD33FFC500 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD3400900E | 14_2_00007FFD3400900E |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD34010A18 | 14_2_00007FFD34010A18 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD33FF9AF2 | 14_2_00007FFD33FF9AF2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD33FF9C50 | 14_2_00007FFD33FF9C50 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD34201895 | 14_2_00007FFD34201895 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD3420693C | 14_2_00007FFD3420693C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD342152AD | 14_2_00007FFD342152AD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD34200B1C | 14_2_00007FFD34200B1C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD3420B8B5 | 14_2_00007FFD3420B8B5 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD34215290 | 14_2_00007FFD34215290 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD34202683 | 14_2_00007FFD34202683 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD342152A8 | 14_2_00007FFD342152A8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 14_2_00007FFD34204706 | 14_2_00007FFD34204706 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 18_3_06C47678 | 18_3_06C47678 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 18_3_06C40040 | 18_3_06C40040 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD33FF8682 | 19_2_00007FFD33FF8682 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD34003FFA | 19_2_00007FFD34003FFA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD3400100A | 19_2_00007FFD3400100A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD33FF78D6 | 19_2_00007FFD33FF78D6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD33FFFA94 | 19_2_00007FFD33FFFA94 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD33FFBD10 | 19_2_00007FFD33FFBD10 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD33FFDE1D | 19_2_00007FFD33FFDE1D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD340010C0 | 19_2_00007FFD340010C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD33FF9A20 | 19_2_00007FFD33FF9A20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD340082EF | 19_2_00007FFD340082EF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD33FF12FB | 19_2_00007FFD33FF12FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 19_2_00007FFD340093F2 | 19_2_00007FFD340093F2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD3401047D | 21_2_00007FFD3401047D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD33FFFA94 | 21_2_00007FFD33FFFA94 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD34003FFA | 21_2_00007FFD34003FFA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD3400100A | 21_2_00007FFD3400100A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD340010C0 | 21_2_00007FFD340010C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD34008181 | 21_2_00007FFD34008181 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD33FFBDB0 | 21_2_00007FFD33FFBDB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD33FFDE1D | 21_2_00007FFD33FFDE1D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD340082EF | 21_2_00007FFD340082EF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD340093F2 | 21_2_00007FFD340093F2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD33FF8682 | 21_2_00007FFD33FF8682 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD33FF78D6 | 21_2_00007FFD33FF78D6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD33FF70D5 | 21_2_00007FFD33FF70D5 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 21_2_00007FFD33FF12FB | 21_2_00007FFD33FF12FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 23_2_00007FFD340018D3 | 23_2_00007FFD340018D3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 23_2_00007FFD340006D3 | 23_2_00007FFD340006D3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 23_2_00007FFD340012FB | 23_2_00007FFD340012FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 23_2_00007FFD340005FA | 23_2_00007FFD340005FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 23_2_00007FFD34000740 | 23_2_00007FFD34000740 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD3402D784 | 25_2_00007FFD3402D784 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD3404F820 | 25_2_00007FFD3404F820 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD3404C850 | 25_2_00007FFD3404C850 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34032063 | 25_2_00007FFD34032063 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34033CE0 | 25_2_00007FFD34033CE0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD3402CD90 | 25_2_00007FFD3402CD90 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34021DC8 | 25_2_00007FFD34021DC8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD3402CEB0 | 25_2_00007FFD3402CEB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD3402D3D8 | 25_2_00007FFD3402D3D8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34029446 | 25_2_00007FFD34029446 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34030F3A | 25_2_00007FFD34030F3A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34021A8B | 25_2_00007FFD34021A8B |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34021AB8 | 25_2_00007FFD34021AB8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD3402FAD0 | 25_2_00007FFD3402FAD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD341910CD | 25_2_00007FFD341910CD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD3423E46D | 25_2_00007FFD3423E46D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD3423B6BD | 25_2_00007FFD3423B6BD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34236FC8 | 25_2_00007FFD34236FC8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD342207B5 | 25_2_00007FFD342207B5 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34237050 | 25_2_00007FFD34237050 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34231137 | 25_2_00007FFD34231137 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34238688 | 25_2_00007FFD34238688 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD3423D021 | 25_2_00007FFD3423D021 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD342398A1 | 25_2_00007FFD342398A1 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD342438FA | 25_2_00007FFD342438FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 25_2_00007FFD34010C58 | 25_2_00007FFD34010C58 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD340466B0 | 28_2_00007FFD340466B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD34029702 | 28_2_00007FFD34029702 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD34041730 | 28_2_00007FFD34041730 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD3404C798 | 28_2_00007FFD3404C798 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD34028956 | 28_2_00007FFD34028956 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD340361E8 | 28_2_00007FFD340361E8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD3402C2C8 | 28_2_00007FFD3402C2C8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD340212FB | 28_2_00007FFD340212FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD3402664D | 28_2_00007FFD3402664D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD34020730 | 28_2_00007FFD34020730 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD34040098 | 28_2_00007FFD34040098 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD3402712D | 28_2_00007FFD3402712D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD34028155 | 28_2_00007FFD34028155 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD34035B31 | 28_2_00007FFD34035B31 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 28_2_00007FFD3403D350 | 28_2_00007FFD3403D350 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FF8476 | 33_2_00007FFD33FF8476 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FF15FD | 33_2_00007FFD33FF15FD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FE3EFA | 33_2_00007FFD33FE3EFA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FF6F59 | 33_2_00007FFD33FF6F59 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FF3810 | 33_2_00007FFD33FF3810 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FFC865 | 33_2_00007FFD33FFC865 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD340019B0 | 33_2_00007FFD340019B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FF52FA | 33_2_00007FFD33FF52FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FE6590 | 33_2_00007FFD33FE6590 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FE0ED3 | 33_2_00007FFD33FE0ED3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FE06D3 | 33_2_00007FFD33FE06D3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FE0740 | 33_2_00007FFD33FE0740 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FE0838 | 33_2_00007FFD33FE0838 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FE1080 | 33_2_00007FFD33FE1080 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FFF0C2 | 33_2_00007FFD33FFF0C2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FFF120 | 33_2_00007FFD33FFF120 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FFF1D3 | 33_2_00007FFD33FFF1D3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FE11F2 | 33_2_00007FFD33FE11F2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD34001A78 | 33_2_00007FFD34001A78 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD34001A80 | 33_2_00007FFD34001A80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD34001AAB | 33_2_00007FFD34001AAB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FE12DF | 33_2_00007FFD33FE12DF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FFF2FA | 33_2_00007FFD33FFF2FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FF53E8 | 33_2_00007FFD33FF53E8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD33FE13F3 | 33_2_00007FFD33FE13F3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B706960 | 37_2_00007FFD8B706960 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B7101E0 | 37_2_00007FFD8B7101E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B7020E0 | 37_2_00007FFD8B7020E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B65B880 | 37_2_00007FFD8B65B880 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B628B90 | 37_2_00007FFD8B628B90 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B67CC00 | 37_2_00007FFD8B67CC00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5F6A80 | 37_2_00007FFD8B5F6A80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B69AA70 | 37_2_00007FFD8B69AA70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B618A60 | 37_2_00007FFD8B618A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B64CB50 | 37_2_00007FFD8B64CB50 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6BAB00 | 37_2_00007FFD8B6BAB00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B62E990 | 37_2_00007FFD8B62E990 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5D8A3C | 37_2_00007FFD8B5D8A3C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5D28C0 | 37_2_00007FFD8B5D28C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6288A0 | 37_2_00007FFD8B6288A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5E8860 | 37_2_00007FFD8B5E8860 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B696860 | 37_2_00007FFD8B696860 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6C6910 | 37_2_00007FFD8B6C6910 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B66EFD0 | 37_2_00007FFD8B66EFD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B61AFB0 | 37_2_00007FFD8B61AFB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5E2F8C | 37_2_00007FFD8B5E2F8C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B619020 | 37_2_00007FFD8B619020 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5DCEA8 | 37_2_00007FFD8B5DCEA8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5FCE70 | 37_2_00007FFD8B5FCE70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5D4DB4 | 37_2_00007FFD8B5D4DB4 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B70CD60 | 37_2_00007FFD8B70CD60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B630E30 | 37_2_00007FFD8B630E30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B61ACD0 | 37_2_00007FFD8B61ACD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5E6CC0 | 37_2_00007FFD8B5E6CC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B720D30 | 37_2_00007FFD8B720D30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B704C80 | 37_2_00007FFD8B704C80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B656D20 | 37_2_00007FFD8B656D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B698D20 | 37_2_00007FFD8B698D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B644D00 | 37_2_00007FFD8B644D00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6722B0 | 37_2_00007FFD8B6722B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5F0330 | 37_2_00007FFD8B5F0330 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B698310 | 37_2_00007FFD8B698310 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5F2310 | 37_2_00007FFD8B5F2310 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B67A2F0 | 37_2_00007FFD8B67A2F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B642240 | 37_2_00007FFD8B642240 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B68C220 | 37_2_00007FFD8B68C220 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B66A0C0 | 37_2_00007FFD8B66A0C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6740A0 | 37_2_00007FFD8B6740A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B65C110 | 37_2_00007FFD8B65C110 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5DE80C | 37_2_00007FFD8B5DE80C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B66A7E0 | 37_2_00007FFD8B66A7E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B70C680 | 37_2_00007FFD8B70C680 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5EE720 | 37_2_00007FFD8B5EE720 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5E2738 | 37_2_00007FFD8B5E2738 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B68A5D0 | 37_2_00007FFD8B68A5D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6F05D0 | 37_2_00007FFD8B6F05D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5D85D4 | 37_2_00007FFD8B5D85D4 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6B6590 | 37_2_00007FFD8B6B6590 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B68E590 | 37_2_00007FFD8B68E590 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B70E5B0 | 37_2_00007FFD8B70E5B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B650600 | 37_2_00007FFD8B650600 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5E44DC | 37_2_00007FFD8B5E44DC |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6364A0 | 37_2_00007FFD8B6364A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B654550 | 37_2_00007FFD8B654550 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5DA524 | 37_2_00007FFD8B5DA524 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B620510 | 37_2_00007FFD8B620510 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B619BA0 | 37_2_00007FFD8B619BA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B713C20 | 37_2_00007FFD8B713C20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6BDB80 | 37_2_00007FFD8B6BDB80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5FBBE0 | 37_2_00007FFD8B5FBBE0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B605AD0 | 37_2_00007FFD8B605AD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B609A60 | 37_2_00007FFD8B609A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B687A60 | 37_2_00007FFD8B687A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B637B30 | 37_2_00007FFD8B637B30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B673AF0 | 37_2_00007FFD8B673AF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B63B9F0 | 37_2_00007FFD8B63B9F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6318DA | 37_2_00007FFD8B6318DA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5FD910 | 37_2_00007FFD8B5FD910 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B66FED0 | 37_2_00007FFD8B66FED0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5D7EC0 | 37_2_00007FFD8B5D7EC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B653EB0 | 37_2_00007FFD8B653EB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B685EA0 | 37_2_00007FFD8B685EA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B677EA0 | 37_2_00007FFD8B677EA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B617E70 | 37_2_00007FFD8B617E70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B609F30 | 37_2_00007FFD8B609F30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B665F20 | 37_2_00007FFD8B665F20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5E7F30 | 37_2_00007FFD8B5E7F30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B62FEF0 | 37_2_00007FFD8B62FEF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5E5E50 | 37_2_00007FFD8B5E5E50 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B603E10 | 37_2_00007FFD8B603E10 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6BBCD0 | 37_2_00007FFD8B6BBCD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6ADCC0 | 37_2_00007FFD8B6ADCC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6A7D20 | 37_2_00007FFD8B6A7D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B619CF0 | 37_2_00007FFD8B619CF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5F93D0 | 37_2_00007FFD8B5F93D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B66B370 | 37_2_00007FFD8B66B370 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6AF3E0 | 37_2_00007FFD8B6AF3E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5DD284 | 37_2_00007FFD8B5DD284 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B66D350 | 37_2_00007FFD8B66D350 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5DF340 | 37_2_00007FFD8B5DF340 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B63F1B0 | 37_2_00007FFD8B63F1B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5D11B0 | 37_2_00007FFD8B5D11B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B669170 | 37_2_00007FFD8B669170 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B64F220 | 37_2_00007FFD8B64F220 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6E3200 | 37_2_00007FFD8B6E3200 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B7050F0 | 37_2_00007FFD8B7050F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B62F780 | 37_2_00007FFD8B62F780 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B721840 | 37_2_00007FFD8B721840 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B61D770 | 37_2_00007FFD8B61D770 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B71F790 | 37_2_00007FFD8B71F790 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5ED830 | 37_2_00007FFD8B5ED830 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6C56D0 | 37_2_00007FFD8B6C56D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B671690 | 37_2_00007FFD8B671690 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B677720 | 37_2_00007FFD8B677720 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B6436E0 | 37_2_00007FFD8B6436E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5E5640 | 37_2_00007FFD8B5E5640 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B63B647 | 37_2_00007FFD8B63B647 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B61F630 | 37_2_00007FFD8B61F630 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5DD634 | 37_2_00007FFD8B5DD634 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5D74B0 | 37_2_00007FFD8B5D74B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5D3474 | 37_2_00007FFD8B5D3474 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD8B5D955C | 37_2_00007FFD8B5D955C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3400F78D | 37_2_00007FFD3400F78D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3400ED6D | 37_2_00007FFD3400ED6D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34005661 | 37_2_00007FFD34005661 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD340037FA | 37_2_00007FFD340037FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3400D126 | 37_2_00007FFD3400D126 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3400BD61 | 37_2_00007FFD3400BD61 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34006011 | 37_2_00007FFD34006011 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3400B955 | 37_2_00007FFD3400B955 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34003978 | 37_2_00007FFD34003978 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3422F728 | 37_2_00007FFD3422F728 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD342232A6 | 37_2_00007FFD342232A6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD342224E8 | 37_2_00007FFD342224E8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34222558 | 37_2_00007FFD34222558 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3422ADD8 | 37_2_00007FFD3422ADD8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34226058 | 37_2_00007FFD34226058 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3422F088 | 37_2_00007FFD3422F088 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34222BCF | 37_2_00007FFD34222BCF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34333C71 | 37_2_00007FFD34333C71 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34334D17 | 37_2_00007FFD34334D17 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3432859D | 37_2_00007FFD3432859D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3432B95D | 37_2_00007FFD3432B95D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3432E965 | 37_2_00007FFD3432E965 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343312CF | 37_2_00007FFD343312CF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3432FA85 | 37_2_00007FFD3432FA85 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34330D15 | 37_2_00007FFD34330D15 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34332698 | 37_2_00007FFD34332698 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34334E99 | 37_2_00007FFD34334E99 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34329809 | 37_2_00007FFD34329809 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34332140 | 37_2_00007FFD34332140 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343308F2 | 37_2_00007FFD343308F2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3432B0F2 | 37_2_00007FFD3432B0F2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3432F219 | 37_2_00007FFD3432F219 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34326B2D | 37_2_00007FFD34326B2D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343312FB | 37_2_00007FFD343312FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3432FAFA | 37_2_00007FFD3432FAFA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343F346A | 37_2_00007FFD343F346A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343F9478 | 37_2_00007FFD343F9478 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343FA29F | 37_2_00007FFD343FA29F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343FACB8 | 37_2_00007FFD343FACB8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343F0B77 | 37_2_00007FFD343F0B77 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343FF378 | 37_2_00007FFD343FF378 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343F4F88 | 37_2_00007FFD343F4F88 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD343FF458 | 37_2_00007FFD343FF458 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD344032DC | 37_2_00007FFD344032DC |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD344056D8 | 37_2_00007FFD344056D8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34407E68 | 37_2_00007FFD34407E68 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34407F48 | 37_2_00007FFD34407F48 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34407158 | 37_2_00007FFD34407158 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3440F168 | 37_2_00007FFD3440F168 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34408D7F | 37_2_00007FFD34408D7F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3440502F | 37_2_00007FFD3440502F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34409A58 | 37_2_00007FFD34409A58 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34433EC1 | 37_2_00007FFD34433EC1 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34599C65 | 37_2_00007FFD34599C65 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD3459C928 | 37_2_00007FFD3459C928 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD345A3DF5 | 37_2_00007FFD345A3DF5 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD345902D7 | 37_2_00007FFD345902D7 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34596A67 | 37_2_00007FFD34596A67 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD34591A0D | 37_2_00007FFD34591A0D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 37_2_00007FFD345A3F80 | 37_2_00007FFD345A3F80 |