Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe.config | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\Newtonsoft.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\Pubnub.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\.version | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.runtimeconfig.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.deps.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.SecureString.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.ServicePoint.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Uri.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.CoreLib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Algorithms.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\netstandard.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr\6.0.35\hostfxr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\dotnet.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\LICENSE.txt | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\ThirdPartyNotices.txt | Jump to behavior |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENT.PACKAGE.WATCHDOG/1.7/AGENT.PACKAGE.WATCHDOG.ZIP |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148967C2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEADREMOTE/6.0/AGENTPACKAGEADREMOTE.ZIP |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD07B8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEAGENTINFORMATION/37.9/AGENTPACKAGEAGENTINFORMATI |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148966B7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEHEARTBEAT/17.14/AGENTPACKAGEHEARTBEAT.ZIP |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEINTERNALPOLLER/23.8/AGENTPACKAGEINTERNALPOLLER.Z |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148967C2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEMARKETPLACE/1.6/AGENTPACKAGEMARKETPLACE.ZIP |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148966B7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEMONITORING/37.8/AGENTPACKAGEMONITORING.ZIP |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEOSUPDATES/20.1/AGENTPACKAGEOSUPDATES.ZIP |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEPROGRAMMANAGEMENT/26.0/AGENTPACKAGEPROGRAMMANAGE |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGERUNTIMEINSTALLER/1.6/AGENTPACKAGERUNTIMEINSTALLE |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGESTREMOTE/23.4/AGENTPACKAGESTREMOTE.ZIP |
Source: AteraAgent.exe, 00000018.00000002.2692056998.000001489675C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGESYSTEMTOOLS/27.6/AGENTPACKAGESYSTEMTOOLS.ZIP |
Source: AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE2ADF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://a6dc35606b2c6816e.awsglobalaccelerator.com |
Source: AteraAgent.exe, 0000000C.00000000.1793758201.000001DF0A9F2000.00000002.00000001.01000000.0000000F.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E6E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0651000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896491000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://acontrol.atera.com/ |
Source: rundll32.exe, 00000004.00000002.1771227691.00000000046E5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004EC5000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2033567521.00000224D2C5F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896E0B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.000001489693C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148969DC000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C801C7000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C80250000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2159573235.000001E30057E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://agent-api.atera.com |
Source: rundll32.exe, 00000004.00000002.1771227691.00000000046E5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004EC5000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2033567521.00000224D2C5F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896E0B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.000001489693C000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C801C7000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C80250000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2159573235.000001E30057E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://atera-agent-api-eu.westeurope.cloudapp.azure.com |
Source: AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0556000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ca.disig.sk/ca/crl/ca_disig.crl0 |
Source: AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.d |
Source: AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.dig |
Source: AteraAgent.exe, 0000000D.00000002.2348840998.000002BBCFD98000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/ |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2727562739.00000148AEBF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF00A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B63000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF026000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B12000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFA4000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000000.2233864843.00000000009B5000.00000002.00000001.01000000.00000026.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0CA0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0942000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0E1C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896CE4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D11000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896A50000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896EA8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF251A5000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9321000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0530000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE9150000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896CE4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896AD3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896E0B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896BE7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AEF71000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9321000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF00A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B63000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF026000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B12000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFA4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9321000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE9150000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2034231651.00000224EB28A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2727562739.00000148AEBF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2727562739.00000148AEC4C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF00A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2727562739.00000148AECB2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0 |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0 |
Source: AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE919F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cps.chambersign.org/cps/chambersignroot.html0 |
Source: AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE919F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.chambersign.org/chambersignroot.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9308000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digice |
Source: AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/Dig |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2727562739.00000148AEBF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF00A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B63000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF026000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B12000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFA4000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000000.2233864843.00000000009B5000.00000002.00000001.01000000.00000026.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0 |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0= |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF25196000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E8D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF251A5000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9321000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0CA0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0530000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0942000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0E1C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE9150000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896CE4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896AD3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlM |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E8D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlpeYe |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHAA |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9321000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF00A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B63000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF026000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B12000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF25170000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: System.Diagnostics.DiagnosticSource.dll1.24.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crlL |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF25170000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/G |
Source: AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/Im |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF25170000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/l |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02 |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF25170000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlrlCache |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF25170000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com:80/DigiCertTrustedRootG4.crlocalLow |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.come |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTruGm |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF25196000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E8D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0CA0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0942000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0E1C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896CE4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D11000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896A50000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896EA8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF251A5000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9321000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0530000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE9150000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896CE4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896AD3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896E0B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896BE7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AEF71000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF251A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl9YOd |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF25196000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlbc |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E8D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crleeBe |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0= |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF25170000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/c |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF251A5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl#_Dd |
Source: AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE9150000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
Source: AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD05F6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/enP |
Source: AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE2B21000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://d17kmd0va0f0mp.cloudfront.net |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://d25btwd9wax8gu.cloudfront.net |
Source: AgentPackageAgentInformation.exe, 00000014.00000000.2006129029.00000224D2072000.00000002.00000001.01000000.00000016.sdmp | String found in binary or memory: http://dl.google.com/googletalk/googletalk-setup.exe |
Source: AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE2B21000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://download.splashtop.com |
Source: AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://fedir.comsign.co.il/crl/ComSignCA.crl0 |
Source: AgentPackageAgentInformation.exe, 00000016.00000002.2049207030.0000017BC9259000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.microsoft.cofw8 |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2183670936.000001E369D02000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: http://james.newtonking.com/projects/json |
Source: rundll32.exe, 00000010.00000002.1904488118.00000000076F7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://microsoft.co |
Source: AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE2ADF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://my.splashtop.com |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/dummynamespace/ |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/ |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/3 |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/5 |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverOneWayServer/ProcessLogMessages |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverServer/ProcessLogMessagesResponsep |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverServer/ProcessLogMessagesT |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://nlog-project.org/ws/T |
Source: AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocs.pt |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digice |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digice0N |
Source: AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.c |
Source: AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.cBo |
Source: AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF25170000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/ |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24EF6000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E8D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rh |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24EF6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxX |
Source: AteraAgent.exe, 0000000C.00000002.1856509849.000001DF251A5000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9321000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0CA0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0530000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0942000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0E1C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE9150000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896CE4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896AD3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9321000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE9150000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2034231651.00000224EB28A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2727562739.00000148AEBF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2727562739.00000148AEC4C000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF00A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2727562739.00000148AECB2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0A |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2727562739.00000148AEBF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF00A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B63000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF026000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B12000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFA4000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000000.2233864843.00000000009B5000.00000002.00000001.01000000.00000026.sdmp | String found in binary or memory: http://ocsp.digicert.com0C |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://ocsp.digicert.com0K |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://ocsp.digicert.com0N |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://ocsp.digicert.com0O |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9321000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF00A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B63000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2731087701.00000148AF026000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B12000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0X |
Source: AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRS |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E8D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com:80/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF |
Source: AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E6E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertAssuredIDRootCA.crl |
Source: AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0556000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2727562739.00000148AEC4C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.cr |
Source: AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0556000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: AteraAgent.exe, 00000018.00000002.2731087701.00000148AEF66000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crlV |
Source: AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE919F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.ncdc.gov.sa0 |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ocsp.thawte.com0 |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ps.atera.com |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ps.pndsn.com |
Source: xdnup.dll.1.dr | String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0 |
Source: xdnup.dll.1.dr | String found in binary or memory: http://s2.symcb.com0 |
Source: AteraAgent.exe, 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org |
Source: AteraAgent.exe, 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp, System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/ |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.Collections.GenericJ |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.IO |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.Runtime.Serialization |
Source: AteraAgent.exe, 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.ServiceProcess |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.Xml |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/SystemV |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/SystemY |
Source: System.Private.DataContractSerialization.dll.1.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/dhttp://schemas.datacontract.org/2004/07/System.XmlRhttp://w |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: rundll32.exe, 00000004.00000002.1771227691.0000000004621000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1771227691.00000000046C4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0651000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004E01000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004EA4000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2033567521.00000224D2BB3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896491000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C8022B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C80001000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE29F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2159573235.000001E3000ED000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: xdnup.dll.1.dr | String found in binary or memory: http://sv.symcb.com/sv.crl0a |
Source: xdnup.dll.1.dr | String found in binary or memory: http://sv.symcb.com/sv.crt0 |
Source: xdnup.dll.1.dr | String found in binary or memory: http://sv.symcd.com0& |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: xdnup.dll.1.dr, stdpms.cat.1.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE919F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://web.ncdc.gov.sa/crl/nrcacomb1.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE919F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://web.ncdc.gov.sa/crl/nrcaparta1.crl |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: http://wixtoolset.org |
Source: rundll32.exe, 00000003.00000003.1720745521.000000000427D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.0000000004398000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004AF5000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004A9A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v |
Source: rundll32.exe, 00000003.00000003.1720745521.000000000427D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.0000000004398000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004AF5000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004A9A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/news/ |
Source: rundll32.exe, 00000003.00000003.1720745521.000000000427D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.0000000004398000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004AF5000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004A9A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/releases/ |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2178916823.000001E3699A2000.00000002.00000001.01000000.0000001F.sdmp | String found in binary or memory: http://www.abit.com.tw/ |
Source: AteraAgent.exe, 0000000D.00000002.2398127205.000002BBE934E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.ancert.com/cps0 |
Source: AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.certplus.com/CRL/class2.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.certplus.com/CRL/class3.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE919F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.chambersign.org1 |
Source: AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0556000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.datev.de/zertifikat-policy-int0 |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0CA0000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0942000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0E1C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896CE4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D11000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896A50000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896EA8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1856509849.000001DF251A5000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1854401612.000001DF24E10000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE9321000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0530000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2394976270.000002BBE924D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE9150000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896CE4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896AD3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896E0B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0556000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.disig.sk/ca/crl/ca_disig.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2355737421.000002BBD0556000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.disig.sk/ca0f |
Source: rundll32.exe, 00000010.00000002.1904488118.00000000076F7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.microsoft.c |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896A50000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.nlog-project.org/schemas/NLog.xsd |
Source: xdnup.dll.1.dr | String found in binary or memory: http://www.symauth.com/cps0( |
Source: xdnup.dll.1.dr | String found in binary or memory: http://www.symauth.com/rpa00 |
Source: AteraAgent.exe, 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.o |
Source: AteraAgent.exe, 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.oh |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896DE1000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C8022B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C80297000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.P |
Source: rundll32.exe, 00000004.00000002.1771227691.00000000046C4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004EA4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.aterD |
Source: rundll32.exe, 00000003.00000003.1720745521.000000000427D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1771227691.0000000004621000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1771227691.00000000046C4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.0000000004398000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004AF5000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0651000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004E01000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004A9A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004EA4000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2033567521.00000224D2BB3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.000001489693C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896491000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896DE1000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C8022B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C80001000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C801C7000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2159573235.000001E3000ED000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com |
Source: rundll32.exe, 00000003.00000003.1720745521.000000000427D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1771227691.0000000004621000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1771227691.00000000046C4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.0000000004398000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004AF5000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004E01000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004A9A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004EA4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/ |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C80297000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Prh |
Source: AgentPackageAgentInformation.exe, 00000014.00000002.2033567521.00000224D2BB3000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C801C7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896DE1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/A |
Source: rundll32.exe, 00000003.00000003.1720745521.000000000427D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1771227691.0000000004621000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1771227691.00000000046C4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.0000000004398000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004AF5000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD07B8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004E01000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004A9A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004EA4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/ |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AcknowledgeCommands |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06FA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AgentStarting |
Source: AgentPackageAgentInformation.exe, 00000014.00000002.2033567521.00000224D2BB3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/CommandResult |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06D4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.000001489693C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetCommands |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06FA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetCommandsFallback |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0651000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetEnvironmentStatus |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0651000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetRecurringPackages |
Source: AteraAgent.exe, 00000018.00000002.2692056998.000001489651A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetRecurringPackages.p |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896DE1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/Trace |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C8022B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/ |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C8022B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C80001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/script-based |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C80297000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/guiComm |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C80297000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C80093000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/guiCommandResult |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C801F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2291545268.0000014C801C7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/recurringCommandResult |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2179127584.000001E369AE5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/thresholds/a6dedb0f-2022-4aea-abf1-f34b9f20892e |
Source: rundll32.exe, 00000004.00000002.1771227691.0000000004621000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1771227691.00000000046C4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004E01000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004EA4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/track-event |
Source: rundll32.exe, 00000004.00000002.1771227691.0000000004706000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1903585125.0000000004EE6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/track-event; |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.comR |
Source: System.Diagnostics.EventLog.dll.24.dr | String found in binary or memory: https://aka.ms/binaryformatter |
Source: System.Diagnostics.EventLog.dll.24.dr | String found in binary or memory: https://aka.ms/dotnet-warnings/ |
Source: System.Diagnostics.EventLog.dll.24.dr | String found in binary or memory: https://aka.ms/serializationformat-binary-obsolete |
Source: xdnup.dll.1.dr | String found in binary or memory: https://d.symcb.com/cps0% |
Source: xdnup.dll.1.dr | String found in binary or memory: https://d.symcb.com/rpa0 |
Source: AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE2B05000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://download.splashtop.com |
Source: AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE2B01000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE2B05000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE2ADF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://download.splashtop.com/csrs/Splashtop_Streamer_Win_DEPLOY_INSTALLER_v3.7.2.3.exe |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2033244997.00000224D2A72000.00000002.00000001.01000000.00000019.sdmp, AgentPackageSTRemote.exe, 00000020.00000002.2691785056.000001EDFB110000.00000002.00000001.01000000.0000002B.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2183670936.000001E369D02000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: https://github.com/JamesNK/Newtonsoft.Json |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/dotnet/corefx/tree/30ab651fcb4354552bd4891619a0bdd81e0ebdbf |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/dotnet/corefx/tree/30ab651fcb4354552bd4891619a0bdd81e0ebdbf8 |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B12000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/dotnet/corefx/tree/32b491939fbd125f304031c35038b1e14b4e3958 |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896B12000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/dotnet/corefx/tree/32b491939fbd125f304031c35038b1e14b4e39588 |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/dotnet/corefx/tree/7601f4f6225089ffb291dc7d58293c7bbf5c5d4f |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/dotnet/corefx/tree/7601f4f6225089ffb291dc7d58293c7bbf5c5d4f8 |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, System.IO.FileSystem.Primitives.dll.1.dr, System.IO.IsolatedStorage.dll.1.dr, System.Security.Cryptography.Cng.dll.1.dr, System.Reflection.Emit.dll.1.dr, System.Xml.XDocument.dll.1.dr, System.Private.DataContractSerialization.dll.1.dr, Microsoft.CSharp.dll.1.dr, Microsoft.Extensions.FileSystemGlobbing.dll.24.dr, System.Diagnostics.EventLog.dll.24.dr, System.Threading.Tasks.Dataflow.dll.1.dr, System.Reflection.Primitives.dll.1.dr, System.Data.Common.dll.1.dr | String found in binary or memory: https://github.com/dotnet/runtime |
Source: System.Threading.Tasks.Dataflow.dll.1.dr | String found in binary or memory: https://github.com/dotnet/runtimew |
Source: AteraAgent.exe, 0000000D.00000002.2398959302.000002BBE95A2000.00000002.00000001.01000000.00000029.sdmp | String found in binary or memory: https://github.com/icsharpcode/SharpZipLib |
Source: System.Data.Common.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1187 |
Source: Microsoft.CSharp.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1416. |
Source: Microsoft.CSharp.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1906. |
Source: System.Data.Common.dll.1.dr | String found in binary or memory: https://github.com/mono/linker/issues/1981 |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896A50000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/nlog/NLog/wiki/Configuration-file#variables |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896A50000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/nlog/NLog/wiki/Layout-Renderers |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896A50000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/nlog/NLog/wiki/Targets |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896A50000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/nlog/nlog/wiki/Configuration-file |
Source: AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE29F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE2ADA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://my.splashtop.com |
Source: AgentPackageSTRemote.exe, 00000020.00000000.2072061781.000001EDE1F02000.00000002.00000001.01000000.0000001A.sdmp | String found in binary or memory: https://my.splashtop.com/csrs/win |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2183096187.000001E369CF8000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: https://nlog-project.org/ |
Source: AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000023.00000000.2103622822.000001E368842000.00000002.00000001.01000000.0000001B.sdmp | String found in binary or memory: https://packagesstore.blob.core.windows.net/installers/BitDefender/rmm.zip |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.ateH |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.ateHrH |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/a |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/ag |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageA |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAR |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A58000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAg |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAge |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD08BD000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0734000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0838000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0738000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAgentI |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageMonitoring/0.40/AgentPackageMonitoring.z |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A58000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0738000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageSTRemote/2.3/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A58000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageSTRemote/2.3/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.Availability/0.16/Agent.Package.Availability.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06A7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.IotPoc/0.2/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD096C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0734000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0838000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0738000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageAgentInformation/37.9/AgentPackageAgentInformation |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMonitoring/37.8/AgentPackageMonitoring.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageNetworkDiscovery/13.0/AgentPackageNetworkDiscovery |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06A7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageRuntimeInstaller/1.5/AgentPackageRuntimeInstaller. |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A58000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0738000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A58000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSTRemote/23.4/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06A7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageTaskScheduler/13.0/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Availability/0.16/Agent.Package.Availability.z |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06A7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.IotPoc/0.2/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip?lE1JX9 |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageADRemote/6.0/AgentPackageADRemote.zip |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148967C2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageADRemote/6.0/AgentPackageADRemote.zip?lE1JX9mqJo |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD07B8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0734000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0838000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0738000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageAgentInformation/37.9/AgentPackageAgentInformati |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageHeartbeat/17.14/AgentPackageHeartbeat.zip |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148966B7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageHeartbeat/17.14/AgentPackageHeartbeat.zip?lE1JX9 |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageInternalPoller/23.8/AgentPackageInternalPoller.z |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMarketplace/1.6/AgentPackageMarketplace.zip |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148967C2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMarketplace/1.6/AgentPackageMarketplace.zip?lE1J |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148966B7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip?lE1JX |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageNetworkDiscovery/23.9/AgentPackageNetworkDiscove |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageOsUpdates/20.1/AgentPackageOsUpdates.zip |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageOsUpdates/20.1/AgentPackageOsUpdates.zip?lE1JX9m |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageProgramManagement/26.0/AgentPackageProgramManage |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06A7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageRuntimeInstaller/1.6/AgentPackageRuntimeInstalle |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A58000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0738000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip?lE1JX9mqJ |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A58000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSystemTools/27.6/AgentPackageSystemTools.zip |
Source: AteraAgent.exe, 00000018.00000002.2692056998.000001489675C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSystemTools/27.6/AgentPackageSystemTools.zip?lE1 |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06A7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTaskScheduler/17.2/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTicketing/30.1/AgentPackageTicketing.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageUpgradeAgent/27.2/AgentPackageUpgradeAgent.zip |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageUpgradeAgent/27.2/AgentPackageUpgradeAgent.zip?l |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageWindowsUpdate/24.6/AgentPackageWindowsUpdate.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.Availability/13.0/Agent.Package.Availability.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06A7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.IotPoc/13.0/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.Watchdog/13.0/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD096C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0734000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0838000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0738000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageAgentInformation/22.7/AgentPackageAgentInformation |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageMonitoring/22.0/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06A7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageRuntimeInstaller/13.0/AgentPackageRuntimeInstaller |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A58000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0738000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageSTRemote/16.0/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD06A7000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0751000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896564000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageTaskScheduler/13.1/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000020.00000002.2671572796.000001EDE29F8000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000020.00000000.2072061781.000001EDE1F02000.00000002.00000001.01000000.0000001A.sdmp | String found in binary or memory: https://ps.atera.com/installers/splashtop/win/SplashtopStreamer.exe |
Source: AteraAgent.exe, 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000020.00000000.2072061781.000001EDE1F02000.00000002.00000001.01000000.0000001A.sdmp | String found in binary or memory: https://ps.atera.com/installers/splashtop/win/SplashtopStreamer.exepUsers/Shared/Splashtop |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD07B8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.comR |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B3F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B3F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.000001489651A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148967A8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=1f7cd882-99b9-4edc-8358-a44cbac962fe |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=246bfa70-210d-46d7-81aa-ffbb467012bf |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=54d33d34-c90c-4ede-831e-f1f741c1dedc |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=74aefc3d-4ad8-443f-9a76-02e92e94cf67 |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD07B8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=7514622b-7504-4e73-83c1-cb213deb3a6a |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=c02a4023-6baa-4600-8d1c-cde6a0bc9950 |
Source: AteraAgent.exe, 00000018.00000002.2692056998.000001489651A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=fdf9888c-209c-49ee-a038-02e568237b90 |
Source: AteraAgent.exe, 00000018.00000002.2692056998.00000148967A8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.000001489651A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/presence/sub_key/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/channel/a6dedb0f |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.2692056998.0000014896578000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/a6dedb0f-2022-4aea-abf1 |
Source: AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.comR |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2185412553.000001E369DC2000.00000002.00000001.01000000.00000025.sdmp | String found in binary or memory: https://system.data.sqlite.org/ |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2186220569.000001E369E24000.00000002.00000001.01000000.00000025.sdmp | String found in binary or memory: https://system.data.sqlite.org/X |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2185412553.000001E369DC2000.00000002.00000001.01000000.00000025.sdmp | String found in binary or memory: https://urn.to/r/sds_see |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, z8yxMFhhZI.msi | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.newtonsoft.com/json |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2183670936.000001E369D02000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: https://www.newtonsoft.com/jsonschema |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2181193022.000001E369C22000.00000002.00000001.01000000.00000022.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2183096187.000001E369CF8000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: https://www.nuget.org/packages/NLog.Web.AspNetCore |
Source: rundll32.exe, 00000003.00000003.1720745521.00000000042AE000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1731658678.00000000043C9000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1773764408.0000000004B26000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1862097536.0000000004ACB000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2033244997.00000224D2A72000.00000002.00000001.01000000.00000019.sdmp, AgentPackageSTRemote.exe, 00000020.00000002.2691785056.000001EDFB110000.00000002.00000001.01000000.0000002B.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2183670936.000001E369D02000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: https://www.nuget.org/packages/Newtonsoft.Json.Bson |
Source: PreVerCheck.exe, 00000027.00000000.2233864843.00000000009B5000.00000002.00000001.01000000.00000026.sdmp, libssl-3.dll.1.dr | String found in binary or memory: https://www.openssl.org/H |
Source: AgentPackageMonitoring.exe | String found in binary or memory: https://www.sqlite.org/copyright.html |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2239122661.00007FFDF18B4000.00000002.00000001.01000000.0000001C.sdmp | String found in binary or memory: https://www.sqlite.org/copyright.html2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_3_06A80040 | 4_3_06A80040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_3_070E59A8 | 5_3_070E59A8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_3_070E50B8 | 5_3_070E50B8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_3_070E4D68 | 5_3_070E4D68 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 12_2_00007FFD9B34C922 | 12_2_00007FFD9B34C922 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 12_2_00007FFD9B34BB76 | 12_2_00007FFD9B34BB76 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 12_2_00007FFD9B340C1D | 12_2_00007FFD9B340C1D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B360C58 | 13_2_00007FFD9B360C58 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B37C910 | 13_2_00007FFD9B37C910 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B386020 | 13_2_00007FFD9B386020 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B371CF0 | 13_2_00007FFD9B371CF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B369AF2 | 13_2_00007FFD9B369AF2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B37900E | 13_2_00007FFD9B37900E |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B37CF58 | 13_2_00007FFD9B37CF58 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B571FDB | 13_2_00007FFD9B571FDB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B57FE91 | 13_2_00007FFD9B57FE91 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B5858B8 | 13_2_00007FFD9B5858B8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B57E48D | 13_2_00007FFD9B57E48D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 16_3_07167678 | 16_3_07167678 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 16_3_07160040 | 16_3_07160040 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B35FA94 | 20_2_00007FFD9B35FA94 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B3578D6 | 20_2_00007FFD9B3578D6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B36108C | 20_2_00007FFD9B36108C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B351828 | 20_2_00007FFD9B351828 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B358682 | 20_2_00007FFD9B358682 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B37047D | 20_2_00007FFD9B37047D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B3512FA | 20_2_00007FFD9B3512FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B3610C0 | 20_2_00007FFD9B3610C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B35BDB0 | 20_2_00007FFD9B35BDB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 22_2_00007FFD9B351828 | 22_2_00007FFD9B351828 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 22_2_00007FFD9B3512FA | 22_2_00007FFD9B3512FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 24_2_00007FFD9B33D3E8 | 24_2_00007FFD9B33D3E8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 24_2_00007FFD9B341D78 | 24_2_00007FFD9B341D78 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 24_2_00007FFD9B341D10 | 24_2_00007FFD9B341D10 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 24_2_00007FFD9B549C2D | 24_2_00007FFD9B549C2D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 24_2_00007FFD9B5568B0 | 24_2_00007FFD9B5568B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 24_2_00007FFD9B54AD48 | 24_2_00007FFD9B54AD48 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B358956 | 27_2_00007FFD9B358956 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B36D350 | 27_2_00007FFD9B36D350 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B3512FA | 27_2_00007FFD9B3512FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B3766B0 | 27_2_00007FFD9B3766B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B359702 | 27_2_00007FFD9B359702 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B35C47F | 27_2_00007FFD9B35C47F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B365B31 | 27_2_00007FFD9B365B31 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B350730 | 27_2_00007FFD9B350730 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B3352FA | 32_2_00007FFD9B3352FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B3419B0 | 32_2_00007FFD9B3419B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B336F59 | 32_2_00007FFD9B336F59 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B3315FD | 32_2_00007FFD9B3315FD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B338476 | 32_2_00007FFD9B338476 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B3213F3 | 32_2_00007FFD9B3213F3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B341AA8 | 32_2_00007FFD9B341AA8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B341A78 | 32_2_00007FFD9B341A78 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B341A80 | 32_2_00007FFD9B341A80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B3212DF | 32_2_00007FFD9B3212DF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B33F1D3 | 32_2_00007FFD9B33F1D3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B3211F2 | 32_2_00007FFD9B3211F2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B33F0C2 | 32_2_00007FFD9B33F0C2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B3208D3 | 32_2_00007FFD9B3208D3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B321080 | 32_2_00007FFD9B321080 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B33F120 | 32_2_00007FFD9B33F120 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B320838 | 32_2_00007FFD9B320838 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B320ED3 | 32_2_00007FFD9B320ED3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B3206D3 | 32_2_00007FFD9B3206D3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 32_2_00007FFD9B320740 | 32_2_00007FFD9B320740 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF179B880 | 35_2_00007FFDF179B880 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF18501E0 | 35_2_00007FFDF18501E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF18420E0 | 35_2_00007FFDF18420E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1846960 | 35_2_00007FFDF1846960 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1823200 | 35_2_00007FFDF1823200 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF178F220 | 35_2_00007FFDF178F220 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17A9170 | 35_2_00007FFDF17A9170 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17111B0 | 35_2_00007FFDF17111B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF177F1B0 | 35_2_00007FFDF177F1B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF18450F0 | 35_2_00007FFDF18450F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17EF3E0 | 35_2_00007FFDF17EF3E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17AB370 | 35_2_00007FFDF17AB370 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17393D0 | 35_2_00007FFDF17393D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF171F340 | 35_2_00007FFDF171F340 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17AD350 | 35_2_00007FFDF17AD350 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF171D284 | 35_2_00007FFDF171D284 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF175F630 | 35_2_00007FFDF175F630 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF171D634 | 35_2_00007FFDF171D634 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1725640 | 35_2_00007FFDF1725640 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF177B647 | 35_2_00007FFDF177B647 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF171955C | 35_2_00007FFDF171955C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1713474 | 35_2_00007FFDF1713474 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17174B0 | 35_2_00007FFDF17174B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF172D830 | 35_2_00007FFDF172D830 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1861840 | 35_2_00007FFDF1861840 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF175D770 | 35_2_00007FFDF175D770 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF176F780 | 35_2_00007FFDF176F780 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF185F790 | 35_2_00007FFDF185F790 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17836E0 | 35_2_00007FFDF17836E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17B7720 | 35_2_00007FFDF17B7720 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17B1690 | 35_2_00007FFDF17B1690 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF18056D0 | 35_2_00007FFDF18056D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF177B9F0 | 35_2_00007FFDF177B9F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF173D910 | 35_2_00007FFDF173D910 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17718DA | 35_2_00007FFDF17718DA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF173BBE0 | 35_2_00007FFDF173BBE0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1853C20 | 35_2_00007FFDF1853C20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17FDB80 | 35_2_00007FFDF17FDB80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1759BA0 | 35_2_00007FFDF1759BA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17B3AF0 | 35_2_00007FFDF17B3AF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1777B30 | 35_2_00007FFDF1777B30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1749A60 | 35_2_00007FFDF1749A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17C7A60 | 35_2_00007FFDF17C7A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1745AD0 | 35_2_00007FFDF1745AD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1743E10 | 35_2_00007FFDF1743E10 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1725E50 | 35_2_00007FFDF1725E50 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1759CF0 | 35_2_00007FFDF1759CF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17E7D20 | 35_2_00007FFDF17E7D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17EDCC0 | 35_2_00007FFDF17EDCC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17FBCD0 | 35_2_00007FFDF17FBCD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF176FEF0 | 35_2_00007FFDF176FEF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17A5F20 | 35_2_00007FFDF17A5F20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1727F30 | 35_2_00007FFDF1727F30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1749F30 | 35_2_00007FFDF1749F30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1757E70 | 35_2_00007FFDF1757E70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17C5EA0 | 35_2_00007FFDF17C5EA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17B7EA0 | 35_2_00007FFDF17B7EA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1793EB0 | 35_2_00007FFDF1793EB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1717EC0 | 35_2_00007FFDF1717EC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17AFED0 | 35_2_00007FFDF17AFED0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17CC220 | 35_2_00007FFDF17CC220 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1782240 | 35_2_00007FFDF1782240 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF179C110 | 35_2_00007FFDF179C110 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17B40A0 | 35_2_00007FFDF17B40A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17AA0C0 | 35_2_00007FFDF17AA0C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17BA2F0 | 35_2_00007FFDF17BA2F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1732310 | 35_2_00007FFDF1732310 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17D8310 | 35_2_00007FFDF17D8310 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1730330 | 35_2_00007FFDF1730330 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17B22B0 | 35_2_00007FFDF17B22B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1790600 | 35_2_00007FFDF1790600 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17F6590 | 35_2_00007FFDF17F6590 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17CE590 | 35_2_00007FFDF17CE590 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF184E5B0 | 35_2_00007FFDF184E5B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF18305D0 | 35_2_00007FFDF18305D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17185D4 | 35_2_00007FFDF17185D4 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17CA5D0 | 35_2_00007FFDF17CA5D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1760510 | 35_2_00007FFDF1760510 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF171A524 | 35_2_00007FFDF171A524 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1794550 | 35_2_00007FFDF1794550 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17764A0 | 35_2_00007FFDF17764A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17244DC | 35_2_00007FFDF17244DC |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17AA7E0 | 35_2_00007FFDF17AA7E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF171E80C | 35_2_00007FFDF171E80C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF172E720 | 35_2_00007FFDF172E720 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1722738 | 35_2_00007FFDF1722738 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF184C680 | 35_2_00007FFDF184C680 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1718A3C | 35_2_00007FFDF1718A3C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF176E990 | 35_2_00007FFDF176E990 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1806910 | 35_2_00007FFDF1806910 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1728860 | 35_2_00007FFDF1728860 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17D6860 | 35_2_00007FFDF17D6860 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17688A0 | 35_2_00007FFDF17688A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17128C0 | 35_2_00007FFDF17128C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17BCC00 | 35_2_00007FFDF17BCC00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1768B90 | 35_2_00007FFDF1768B90 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17FAB00 | 35_2_00007FFDF17FAB00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF178CB50 | 35_2_00007FFDF178CB50 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1758A60 | 35_2_00007FFDF1758A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17DAA70 | 35_2_00007FFDF17DAA70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1736A80 | 35_2_00007FFDF1736A80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1770E30 | 35_2_00007FFDF1770E30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF184CD60 | 35_2_00007FFDF184CD60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1714DB4 | 35_2_00007FFDF1714DB4 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1784D00 | 35_2_00007FFDF1784D00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1860D30 | 35_2_00007FFDF1860D30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1796D20 | 35_2_00007FFDF1796D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17D8D20 | 35_2_00007FFDF17D8D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1844C80 | 35_2_00007FFDF1844C80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1726CC0 | 35_2_00007FFDF1726CC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF175ACD0 | 35_2_00007FFDF175ACD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1759020 | 35_2_00007FFDF1759020 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1722F8C | 35_2_00007FFDF1722F8C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF175AFB0 | 35_2_00007FFDF175AFB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF17AEFD0 | 35_2_00007FFDF17AEFD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF173CE70 | 35_2_00007FFDF173CE70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF171CEA8 | 35_2_00007FFDF171CEA8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B33BD61 | 35_2_00007FFD9B33BD61 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B335D0F | 35_2_00007FFD9B335D0F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B33D126 | 35_2_00007FFD9B33D126 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B5531C6 | 35_2_00007FFD9B5531C6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B552AEB | 35_2_00007FFD9B552AEB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B55EFA8 | 35_2_00007FFD9B55EFA8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B654852 | 35_2_00007FFD9B654852 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B664D17 | 35_2_00007FFD9B664D17 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B660CB0 | 35_2_00007FFD9B660CB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B659505 | 35_2_00007FFD9B659505 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B72F444 | 35_2_00007FFD9B72F444 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B72F378 | 35_2_00007FFD9B72F378 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B720A97 | 35_2_00007FFD9B720A97 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B724EA8 | 35_2_00007FFD9B724EA8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B7331F0 | 35_2_00007FFD9B7331F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B8DBB1D | 35_2_00007FFD9B8DBB1D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B8D3D65 | 35_2_00007FFD9B8D3D65 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B8C04E8 | 35_2_00007FFD9B8C04E8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B8C78B1 | 35_2_00007FFD9B8C78B1 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B8D3EF0 | 35_2_00007FFD9B8D3EF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B8CCD90 | 35_2_00007FFD9B8CCD90 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B663C71 | 35_2_00007FFD9B663C71 |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\z8yxMFhhZI.msi" | |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 0665D20C0C89E79051AAD52EC447123B | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSID54C.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5297578 2 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.GenerateAgentId | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSID81C.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5298234 6 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiStart | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIEAF9.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5303046 10 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ShouldContinueInstallation | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding CA0C5DC5313F71A0151B846B9DF49599 E Global\MSI0000 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\net.exe "NET" STOP AteraAgent | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 STOP AteraAgent | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "TaskKill.exe" /f /im AteraAgent.exe | |
Source: C:\Windows\SysWOW64\taskkill.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="marisol.condimentos@hotmail.com" /CompanyId="1" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="" /AccountId="001Q300000ND5FxIAL" /AgentId="a6dedb0f-2022-4aea-abf1-f34b9f20892e" | |
Source: unknown | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSICED.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5311734 32 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiEnd | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" a6dedb0f-2022-4aea-abf1-f34b9f20892e "68b87b08-ee5a-4a28-b15f-bf80d4fa6d54" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 001Q300000ND5FxIAL | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" a6dedb0f-2022-4aea-abf1-f34b9f20892e "6ff523c4-fe05-487b-a560-69e402e17cca" agent-api.atera.com/Production 443 or8ixLi90Mf "identified" 001Q300000ND5FxIAL | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" a6dedb0f-2022-4aea-abf1-f34b9f20892e "0a4bcae9-40bd-4b1b-b8e4-0618fbce3416" agent-api.atera.com/Production 443 or8ixLi90Mf "generalinfo fromGui" 001Q300000ND5FxIAL | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cscript.exe cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe" a6dedb0f-2022-4aea-abf1-f34b9f20892e "e41a296a-bcac-4b5c-8bc7-2e8c101aed07" agent-api.atera.com/Production 443 or8ixLi90Mf "install eyJSbW1Db2RlIjoiaFpDREZQaEs3NW1KIn0=" 001Q300000ND5FxIAL | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\sppsvc.exe C:\Windows\system32\sppsvc.exe | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe" a6dedb0f-2022-4aea-abf1-f34b9f20892e "74fce1a7-1569-4d1d-870e-be0a7f6a226e" agent-api.atera.com/Production 443 or8ixLi90Mf "syncprofile" 001Q300000ND5FxIAL | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\Temp\SplashtopStreamer.exe "C:\Windows\TEMP\SplashtopStreamer.exe" prevercheck /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k smphost | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Process created: C:\Windows\Temp\unpack\PreVerCheck.exe "C:\Windows\Temp\unpack\PreVerCheck.exe" /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Process created: C:\Windows\SysWOW64\msiexec.exe msiexec /norestart /i "setup.msi" /qn /l*v "C:\Windows\TEMP\PreVer.log.txt" CA_EXTPATH=1 USERINFO="sec_opt=0,confirm_d=0,hidewindow=1" | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding F8E5523720913A12EDC79533245EA2A0 E Global\MSI0000 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{59A2717C-22F7-4A43-A7C1-00D51E25C2A7} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{6C9DF522-E68D-4E9E-888D-42C716E8ED46} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{93B32141-75DD-468F-91FD-A34B20052481} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{02BC1A4E-DCC8-4D67-9DD0-6286586A3FE7} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{97507E97-1CE2-42FF-A992-32B34D8B9AF8} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{937EEFBD-E420-4210-82B0-5A755D4DC99D} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{096088E7-31E4-460F-A477-AA5FD56C0C67} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{7C08DB0C-2CD4-44D8-B8C1-2ED1CF4D0265} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{F24D5FAD-F814-47DB-BA4C-8D4C9227B143} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{42674A53-EFF1-4628-AC3D-41E80A5C40CB} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe /C "taskkill.exe /F /IM SRServer.exe /T" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cscript.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 0665D20C0C89E79051AAD52EC447123B | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding CA0C5DC5313F71A0151B846B9DF49599 E Global\MSI0000 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="marisol.condimentos@hotmail.com" /CompanyId="1" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="" /AccountId="001Q300000ND5FxIAL" /AgentId="a6dedb0f-2022-4aea-abf1-f34b9f20892e" | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding F8E5523720913A12EDC79533245EA2A0 E Global\MSI0000 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSID54C.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5297578 2 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.GenerateAgentId | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSID81C.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5298234 6 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiStart | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIEAF9.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5303046 10 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ShouldContinueInstallation | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSICED.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5311734 32 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiEnd | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\net.exe "NET" STOP AteraAgent | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "TaskKill.exe" /f /im AteraAgent.exe | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 STOP AteraAgent | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" a6dedb0f-2022-4aea-abf1-f34b9f20892e "68b87b08-ee5a-4a28-b15f-bf80d4fa6d54" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 001Q300000ND5FxIAL | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" a6dedb0f-2022-4aea-abf1-f34b9f20892e "6ff523c4-fe05-487b-a560-69e402e17cca" agent-api.atera.com/Production 443 or8ixLi90Mf "identified" 001Q300000ND5FxIAL | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" a6dedb0f-2022-4aea-abf1-f34b9f20892e "0a4bcae9-40bd-4b1b-b8e4-0618fbce3416" agent-api.atera.com/Production 443 or8ixLi90Mf "generalinfo fromGui" 001Q300000ND5FxIAL | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe" a6dedb0f-2022-4aea-abf1-f34b9f20892e "e41a296a-bcac-4b5c-8bc7-2e8c101aed07" agent-api.atera.com/Production 443 or8ixLi90Mf "install eyJSbW1Db2RlIjoiaFpDREZQaEs3NW1KIn0=" 001Q300000ND5FxIAL | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe" a6dedb0f-2022-4aea-abf1-f34b9f20892e "74fce1a7-1569-4d1d-870e-be0a7f6a226e" agent-api.atera.com/Production 443 or8ixLi90Mf "syncprofile" 001Q300000ND5FxIAL | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cscript.exe cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\Temp\SplashtopStreamer.exe "C:\Windows\TEMP\SplashtopStreamer.exe" prevercheck /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Process created: C:\Windows\Temp\unpack\PreVerCheck.exe "C:\Windows\Temp\unpack\PreVerCheck.exe" /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Process created: C:\Windows\SysWOW64\msiexec.exe msiexec /norestart /i "setup.msi" /qn /l*v "C:\Windows\TEMP\PreVer.log.txt" CA_EXTPATH=1 USERINFO="sec_opt=0,confirm_d=0,hidewindow=1" | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{59A2717C-22F7-4A43-A7C1-00D51E25C2A7} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{6C9DF522-E68D-4E9E-888D-42C716E8ED46} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{93B32141-75DD-468F-91FD-A34B20052481} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{02BC1A4E-DCC8-4D67-9DD0-6286586A3FE7} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{97507E97-1CE2-42FF-A992-32B34D8B9AF8} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{937EEFBD-E420-4210-82B0-5A755D4DC99D} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{096088E7-31E4-460F-A477-AA5FD56C0C67} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{7C08DB0C-2CD4-44D8-B8C1-2ED1CF4D0265} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{F24D5FAD-F814-47DB-BA4C-8D4C9227B143} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe C:\Windows\TEMP\{218C0E9C-DAE7-402D-9E0D-4FCB02E9E3DA}\_isB2BB.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{42674A53-EFF1-4628-AC3D-41E80A5C40CB} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe /C "taskkill.exe /F /IM SRServer.exe /T" | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msihnd.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srclient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: spp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vssapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vsstrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: riched20.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: usp10.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msls31.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: edputil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wintypes.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: appresolver.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: bcp47langs.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: slc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sppc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: edputil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wintypes.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: appresolver.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: bcp47langs.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: slc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sppc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wscapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wtsapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winsta.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: devobj.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: napinsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wshbth.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: nlaapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptnet.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: wtsapi32.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: version.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: wldp.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: propsys.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: profapi.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: vaultcli.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: edputil.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: netutils.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: samcli.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: netapi32.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: textshaping.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe.config | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\Newtonsoft.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\Pubnub.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\ATERA Networks\AteraAgent\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\.version | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.runtimeconfig.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.deps.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.SecureString.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.ServicePoint.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Uri.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.CoreLib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Algorithms.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\netstandard.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\host\fxr\6.0.35\hostfxr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\dotnet.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\LICENSE.txt | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\ThirdPartyNotices.txt | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIB18D.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PkgHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppAnnotation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSICED.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: 50d410.rbf (copy) | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\ATERA Networks\AteraAgent\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\WBAppVidRec.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSID54C.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x86.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSICED.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI62ED.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRManager.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\dbghelp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI9DAA.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSelfSignCertUtil.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\avutil-55.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiHelper.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIEAF9.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppBrowser.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIEAF9.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\legacy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\64bits\stgamepad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomCtrl32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI7DF9.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDetect.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVirtualDisplay.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiCaptor.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\dotnet.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSID54C.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\ATERA Networks\AteraAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcelt-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsbVhciCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUACCheck.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI1E66.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x64\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcrypto-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\Mirror2Extend.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIA02D.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI4AFC.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libx264-116.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\ARPPRODUCTICON.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSID81C.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\netstandard.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\ATERA Networks\AteraAgent\Pubnub.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stvideo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: 50d412.rbf (copy) | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppBS.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libmp4v2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: 50d415.rbf (copy) | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppED.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Writer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Polly.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSID54C.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperExx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI9EC5.tmp | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSID81C.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppPB.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\PrnPort.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Dapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\qrcodelib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsb.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI9C80.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x64\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SROpus.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\64bits\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264Wrapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIF0E8.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\32bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIC6CB.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\swresample-2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIAE31.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.X509Certificates.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI1954.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRApp.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\sthid.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\hidkmdf.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI2FFE.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: 50d416.rbf (copy) | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrlEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\coreclr.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\setupdrv.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\32bits\stvspk.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Watcher.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\hidkmdf.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK_x86.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\64bits\stvspk.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\32bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\SetupUtil.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\host\fxr\6.0.35\hostfxr.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsbVhciCtrl32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.CoreLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppCam.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.SecureString.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppFileHound.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSID81C.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIEAF9.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIEDAB.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI2687.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI47FD.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAdemWrapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Uri.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAudioChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI232A.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Elevator.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Algorithms.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI4B7A.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\NvFBC.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PinShortCut.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x64\SRWacomUtil64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcurl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\sthid.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdateInstall.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUtility.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeatMini.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIEAF9.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI406.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomUtil32.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSID81C.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSID54C.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdwmark.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Data.SQLite.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: 50d414.rbf (copy) | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: 50d413.rbf (copy) | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI625F.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsb.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIEAF9.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\fips.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIED5C.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\WdfCoInstaller01009.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIA262.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI25CB.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\choco.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\stgamepad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI68CB.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAudioResample.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI634B.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x86\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\WdfCoInstaller01009.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.ServicePoint.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSID54C.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\amf-vcedem-win32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIAD74.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSID81C.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stvideo.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Pubnub.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x64\SRWacomCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\OpenHardwareMonitorLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\taskkill.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\CredentialManagement.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIB18D.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{A1809E80-0C3A-4048-9FED-4F13961294D8}\ISRT.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppAnnotation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSICED.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Interop.WUApiLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\NLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Data.SQLite.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\log4net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.Concurrent.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSID54C.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.ThreadPool.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.FileExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\my_setup.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\avutil-55.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\win\lib\net6.0\System.Diagnostics.EventLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Atera.Agent.Package.Infrastructure.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppBrowser.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Algorithms.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingTrayTMP.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.CompilerServices.VisualC.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Console.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Process.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI7DF9.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Microsoft.Win32.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileSystemGlobbing.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.EventLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingNotifications.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiCaptor.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Security.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.TextWriterTraceListener.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Compression.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Brotli.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcelt-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUACCheck.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Globalization.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Text.RegularExpressions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\Mirror2Extend.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.AppContext.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\AgentPackageHeartbeat.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.Sinks.File.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI4AFC.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\StructureMap.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libx264-116.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\ARPPRODUCTICON.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{F9ECB42B-6BD6-4CC8-99DC-761D336E0CD8}\ISRT.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Buffers.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\ATERA Networks\AteraAgent\Pubnub.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Resources.Writer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.InteropServices.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\system32\SRCredentialProvider.dll (copy) | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XPath.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.EventSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{DDB82D01-A84C-48ED-8A5C-6B19CF655695}\ISRT.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: 50d412.rbf (copy) | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppBS.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: 50d415.rbf (copy) | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libmp4v2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppED.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Calendars.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Buffers.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\QRCoder.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperExx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI9EC5.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppPB.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.Utils.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Dapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.Console.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\CredentialManagement.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Loader.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.SecureString.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\fr\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsb.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI9C80.tmp | Jump to dropped file |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Dropped PE file which has not been started: C:\Windows\Temp\unpack\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x64\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Tracing.dll | Jump to dropped file |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Dropped PE file which has not been started: C:\Windows\Temp\unpack\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SROpus.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\64bits\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{98A0DA3D-3751-4282-8C86-6E890B4959C2}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.Abstractions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\CredentialManagement.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIAE31.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\RunScriptAsUser.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.Watcher.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\win\lib\net6.0\System.ServiceProcess.ServiceController.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tracing.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: 50d416.rbf (copy) | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\setupdrv.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\32bits\stvspk.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\LiteDB.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Options.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.FileVersionInfo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\hidkmdf.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK_x86.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\SetupUtil.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\host\fxr\6.0.35\hostfxr.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TextWriterTraceListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsbVhciCtrl32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Overlapped.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\AgentPackageTicketing.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.UnmanagedMemoryStream.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Binder.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\AgentPackageSystemTools.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\UserDetections.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XPath.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Drawing.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppFileHound.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Timer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.RegularExpressions.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSID81C.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\StructureMap.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\chocolatey.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\EO.WebBrowser.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ComponentModel.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI2687.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.DriveInfo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAudioChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileProviders.Physical.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcurl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\sthid.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Agent.Package.Watchdog.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUtility.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ComponentModel.EventBasedAsync.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSID81C.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomUtil32.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Concurrent.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.DependencyInjection.Abstractions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\SharpSnmpLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: 50d413.rbf (copy) | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.DependencyInjection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsb.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIEAF9.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.FileSystem.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Polly.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\fips.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIED5C.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.Extensions.Logging.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\x64\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-fibers-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.Specialized.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\stgamepad.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI68CB.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Globalization.Calendars.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x86\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\WdfCoInstaller01009.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Microsoft.Win32.TaskScheduler.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIAD74.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Data.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSID81C.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x64\SRWacomCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PkgHelper.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.X509Certificates.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\StructureMap.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Debug.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\AgentPackageRuntimeInstaller.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\AgentPackageUpgradeAgent.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.UserSecrets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\ATERA Networks\AteraAgent\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\WBAppVidRec.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x86.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSICED.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRManager.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI62ED.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI9DAA.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.DataSetExtensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\AgentPackageInternalPoller.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSelfSignCertUtil.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIEAF9.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Diagnostics.EventLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Globalization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{F9ECB42B-6BD6-4CC8-99DC-761D336E0CD8}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIEAF9.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\legacy.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\System32\SRCF3E9.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Options.ConfigurationExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-utility-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\64bits\stgamepad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomCtrl32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDetect.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVirtualDisplay.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Timer.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\dotnet.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.sys | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSID54C.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Atera.AgentCommunication.Models.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\ATERA Networks\AteraAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSICED.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsbVhciCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Hosting.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe TID: 5912 | Thread sleep time: -30000s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1520 | Thread sleep time: -60000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7068 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7248 | Thread sleep count: 3219 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7248 | Thread sleep count: 6512 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7524 | Thread sleep time: -24903104499507879s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7524 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7552 | Thread sleep time: -210000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7664 | Thread sleep time: -2767011611056431s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7548 | Thread sleep time: -90000s >= -30000s | |
Source: C:\Windows\SysWOW64\rundll32.exe TID: 7508 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7840 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7812 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7936 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7988 | Thread sleep count: 6415 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7988 | Thread sleep count: 3070 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 824 | Thread sleep time: -27670116110564310s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 344 | Thread sleep time: -280000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 2872 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 3152 | Thread sleep time: -90000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7260 | Thread sleep count: 4684 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7260 | Thread sleep count: 4389 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -26747778906878833s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -599875s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -599765s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -599656s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -599546s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -599434s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -599327s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -599215s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -598732s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -598624s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -598515s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -598404s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -598296s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -598187s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -598076s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -597967s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -597857s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -597750s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -597640s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -597531s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -597421s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -597312s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -597203s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -597093s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -596977s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -596873s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -596765s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -596344s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -596107s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -595958s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -595839s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -595732s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -595623s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -595515s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -595406s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -595296s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -595187s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 1144 | Thread sleep time: -595078s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7684 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 8156 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep count: 38 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -35048813740048126s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7460 | Thread sleep count: 7361 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -599875s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -599765s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -599639s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -599516s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -599405s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -599297s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -599187s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -599066s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7460 | Thread sleep count: 2229 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -598937s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -598817s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -598687s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -598578s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -598457s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -598328s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -598172s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -598040s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -597920s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -597809s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -597656s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -597491s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -597375s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -597242s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -597121s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -596992s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -596890s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -596778s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -596668s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -596562s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -596451s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -596343s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -596234s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -596115s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -595984s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -595856s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -595743s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -595633s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -595531s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -595421s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -595311s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -595159s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -594907s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -594777s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -594670s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -594544s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -594391s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -594210s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -594062s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -593948s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -593844s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -593719s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -593606s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -593500s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -593389s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -593270s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -593141s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -593016s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -592903s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -592797s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -592686s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -592575s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -592469s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -592359s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7432 | Thread sleep time: -592250s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 7520 | Thread sleep count: 3214 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 7536 | Thread sleep time: -10145709240540247s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 7536 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 4604 | Thread sleep count: 598 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 7420 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 5920 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Windows\Temp\SplashtopStreamer.exe TID: 1184 | Thread sleep time: -33000s >= -30000s | |
Source: C:\Windows\SysWOW64\msiexec.exe TID: 1860 | Thread sleep time: -60000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Thread delayed: delay time: 30000 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Thread delayed: delay time: 90000 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Thread delayed: delay time: 90000 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 600000 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 599875 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 599765 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 599656 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 599546 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 599434 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 599327 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 599215 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 598732 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 598624 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 598515 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 598404 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 598296 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 598187 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 598076 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 597967 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 597857 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 597750 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 597640 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 597531 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 597421 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 597312 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 597203 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 597093 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 596977 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 596873 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 596765 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 596344 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 596107 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 595958 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 595839 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 595732 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 595623 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 595515 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 595406 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 595296 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 595187 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 595078 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 600000 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 599875 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 599765 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 599639 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 599516 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 599405 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 599297 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 599187 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 599066 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 598937 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 598817 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 598687 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 598578 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 598457 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 598328 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 598172 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 598040 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 597920 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 597809 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 597656 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 597491 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 597375 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 597242 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 597121 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 596992 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 596890 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 596778 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 596668 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 596562 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 596451 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 596343 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 596234 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 596115 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 595984 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 595856 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 595743 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 595633 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 595531 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 595421 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 595311 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 595159 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 594907 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 594777 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 594670 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 594544 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 594391 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 594210 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 594062 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 593948 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 593844 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 593719 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 593606 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 593500 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 593389 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 593270 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 593141 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 593016 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 592903 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 592797 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 592686 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 592575 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 592469 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 592359 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Thread delayed: delay time: 592250 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Thread delayed: delay time: 30000 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Thread delayed: delay time: 922337203685477 |
Source: Yara match | File source: 12.0.AteraAgent.exe.1df0a9f0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 24.2.AteraAgent.exe.14896d698a0.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 35.2.AgentPackageMonitoring.exe.1e369090000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 32.0.AgentPackageSTRemote.exe.1ede1f00000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 24.2.AteraAgent.exe.14896b4b638.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 20.2.AgentPackageAgentInformation.exe.224d2990000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 20.0.AgentPackageAgentInformation.exe.224d2070000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 35.0.AgentPackageMonitoring.exe.1e368840000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 24.2.AteraAgent.exe.14896c919d0.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000018.00000002.2731087701.00000148AEF36000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2670881408.000001EDE2350000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2683179432.0000014895B2C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1851255413.000001DF0ABD0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.00000148964FC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2342617373.000000FA9D7A5000.00000004.00000010.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0905000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2298111257.0000014CEA957000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2032657849.00000224D23BB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1853017839.000001DF0C6CC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000003.2061553933.000001C750690000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2175629520.000001C750553000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1852691846.000001DF0AD20000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0CA0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2348840998.000002BBCFD4C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2671572796.000001EDE29F8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2727562739.00000148AEBF0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2348840998.000002BBCFD10000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0A58000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2049207030.0000017BC9190000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.00000148967A8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2682789704.0000014895A20000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000002.1903585125.0000000004E01000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896AD3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2291545268.0000014C80163000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0A1D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2175632565.000001E368AFC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2298111257.0000014CEA999000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2175933613.000001C750670000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2694524998.000001EDFB258000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896E0B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896CE4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2636607693.000001EDE2141000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD06A7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896872000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1851255413.000001DF0ABDC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2636607693.000001EDE218D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0AA5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0D20000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2683179432.0000014895B55000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2683179432.0000014895B0C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2355737421.000002BBD0530000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2189180182.000001E36ABE7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2694524998.000001EDFB227000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1853017839.000001DF0C6F2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2291545268.0000014C8022B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2188031318.000001E36A9C6000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896BE7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2354821548.000002BBCFFF0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0942000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2034231651.00000224EB2AB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.00000148968E0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2050414128.0000017BC9B91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0C6C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2032657849.00000224D2339000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2176993792.000001E369092000.00000002.00000001.01000000.0000001D.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2034231651.00000224EB1F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2175632565.000001E368B7D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2159573235.000001E3005AF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2033567521.00000224D2B31000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2346862466.000002BBCFC90000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD096C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000025.00000002.2601365382.0000000000530000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000005.00000003.1773764408.0000000004AF5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2050143889.0000017BC93F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896D11000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2731087701.00000148AEF20000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000000.2072061781.000001EDE1F02000.00000002.00000001.01000000.0000001A.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD07B8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2636607693.000001EDE2100000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1856509849.000001DF251EE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2312017810.0000014CEBDD1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.000001489691A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2399469390.000002BBE96E9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000003.1862097536.0000000004A9A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896C23000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2176871582.000001E368D90000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2033567521.00000224D2BA3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0E1C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0755000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2731087701.00000148AF00A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896DE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000025.00000002.2601466971.0000000000720000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2399469390.000002BBE96D8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2298111257.0000014CEA910000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2399469390.000002BBE96A8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2348840998.000002BBCFD18000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2033567521.00000224D2BB3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2049207030.0000017BC91AF000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2727562739.00000148AEC4C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2306564317.0000014CEBAF3000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1856509849.000001DF2518E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2291545268.0000014C80093000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2291545268.0000014C801BC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2291545268.0000014C801F8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896491000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1856370967.000001DF25160000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2291545268.0000014C801C7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2032657849.00000224D23C4000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1853017839.000001DF0C6F4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.1771227691.0000000004621000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896E38000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896ABE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000003.1720745521.000000000427D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2689322174.0000014895E00000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2392191319.000002BBE9150000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2671572796.000001EDE2B8F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1853017839.000001DF0C641000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2050414128.0000017BC9C13000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2175632565.000001E368B31000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2731087701.00000148AEF66000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2306758462.0000014CEBAF9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2671572796.000001EDE2B05000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2238998450.00007FFDF18A9000.00000004.00000001.01000000.0000001C.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1851255413.000001DF0AC12000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2175629520.000001C75053B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.00000148966B7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.000001489693C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2694524998.000001EDFB1C0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2298111257.0000014CEA94D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.00000148965A6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2355737421.000002BBD05F6000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0651000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1853017839.000001DF0C6C9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2291545268.0000014C80001000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1853017839.000001DF0C6FA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2187719270.000001E36A7B7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1853017839.000001DF0C7A6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2392191319.000002BBE91A4000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2731087701.00000148AEF9B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896B63000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2174534999.000001E368930000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2636607693.000001EDE2147000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1853017839.000001DF0C772000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000000.2103622822.000001E368842000.00000002.00000001.01000000.0000001B.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2348840998.000002BBCFD98000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2731087701.00000148AEFCD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1853017839.000001DF0C7BC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2187907134.000001E36A9B5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2291545268.0000014C80227000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2175632565.000001E368AF0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000000.1793758201.000001DF0A9F2000.00000002.00000001.01000000.0000000F.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2049207030.0000017BC9218000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2677000286.0000003593725000.00000004.00000010.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2049207030.0000017BC9259000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1853017839.000001DF0C709000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2175632565.000001E368BD6000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896A50000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2032527193.00000224D2260000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0CEE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2032657849.00000224D237D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.00000148969E2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0B67000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2050414128.0000017BC9C03000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.000001489691E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.1771227691.00000000046C4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2731087701.00000148AF026000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896B5D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2049207030.0000017BC9198000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000002.1903585125.0000000004EA4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001F.00000002.2167451224.000002570ABA0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2049207030.0000017BC91CC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2179127584.000001E3699F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2731087701.00000148AEFD9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2636607693.000001EDE2125000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2731087701.00000148AEF50000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000003.1731658678.0000000004398000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2392191319.000002BBE9185000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2301128593.0000014CEAB60000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2032657849.00000224D2331000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD06D4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.000001489675C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896EA8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2357811653.000002BBD0C9E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2394976270.000002BBE930E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896D4B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1851255413.000001DF0AC61000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1851255413.000001DF0AC5B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2032657849.00000224D22F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1857972609.00007FFD9B3D4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2175629520.000001C750530000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2636607693.000001EDE21E8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2636607693.000001EDE210C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.00000148967C2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2291545268.0000014C80297000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2033141606.00000224D2992000.00000002.00000001.01000000.00000018.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2683179432.0000014895AD0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2731087701.00000148AEFA4000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000000.2006129029.00000224D2072000.00000002.00000001.01000000.00000016.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.2692056998.0000014896B12000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2159573235.000001E300001000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000020.00000002.2671572796.000001EDE2981000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2159573235.000001E3000ED000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 2484, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 2676, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 6876, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 7020, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 7196, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 7412, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 7768, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 7884, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 7940, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 8088, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: cmd.exe PID: 1832, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: cscript.exe PID: 7336, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageSTRemote.exe PID: 6036, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageMonitoring.exe PID: 6688, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: SplashtopStreamer.exe PID: 6732, type: MEMORYSTR |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.InstallLog, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF5AA26B837347CAF4.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF313360291D7C6B76.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSICED.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackage.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.CommonLib.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFE1464EAA1FD9BA8D.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFEC36B845F78A3ACD.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFD3CF40D2513F87C8.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\AteraSetupLog.txt, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFCD0592B522CAB70A.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\UserDetections.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF7DB972227FE90FC7.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF0490B689FA32AEF4.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\AgentPackageProgramManagement.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFCDCD475ED65E9D68.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF9F6FD42EB6D08AE2.TMP, type: DROPPED |
Source: Yara match | File source: C:\Config.Msi\50d417.rbs, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFAE89339688091080.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF7EA9ACF5F9FC6CAE.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFD164FC693E7E41FE.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF8A84F97802C3A2A7.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\Microsoft_.NET_Runtime_-_6.0.35_(x64)_20241108075210_001_dotnet_hostfxr_6.0.35_win_x64.msi.log, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFEE2A53A48B336AC3.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF706722BCB30CA3CA.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFA9891912E7317834.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF18FC13D9683BBED2.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\AgentPackageUpgradeAgent.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.ModelsV3.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF2073CE39DF7B5067.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF010EB22A91E7F034.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF90C17B8167754151.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF26378A7BA606BAFD.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF6C0291E02F452261.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSI624E.tmp, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIEAF9.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\AgentPackageADRemote.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.CommonLib.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\AgentPackageInternalPoller.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF86A68179485913BB.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingPackageExtensions.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF07348613B0C561AE.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF8CEB021710F2C2B3.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSID54C.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF453E2092A3D8365F.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\RestartReminder.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFC32A38D1C46623D0.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF41A5E0429566F085.TMP, type: DROPPED |
Source: Yara match | File source: C:\Config.Msi\50d40f.rbs, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIED2C.tmp, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF3204F456716B36CD.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\inprogressinstallinfo.ipi, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFA830C2DE52EC24A3.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSID81C.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\Microsoft_.NET_Runtime_-_6.0.35_(x64)_20241108075210_002_dotnet_host_6.0.35_win_x64.msi.log, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFAD094FD10857892E.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\System32\InstallUtil.InstallLog, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\AgentPackageTicketing.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\AgentPackageRuntimeInstaller.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFCAD91CD85BB3FE25.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF026EBC3EB2941CD9.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\Microsoft_.NET_Runtime_-_6.0.35_(x64)_20241108075210_000_dotnet_runtime_6.0.35_win_x64.msi.log, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\AgentPackageSystemTools.exe, type: DROPPED |
Source: Yara match | File source: C:\Config.Msi\50d405.rbs, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF3CB1399B3D4C602A.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF14A5FA179E65F7D1.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSI44DF.tmp, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe, type: DROPPED |