Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\.version | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.runtimeconfig.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.deps.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to behavior |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGEMONITORING/37.8/AGENTPACKAGEMONITORING.ZIP |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: HTTPS://PS.ATERA.COM/AGENTPACKAGESNET45/AGENTPACKAGESTREMOTE/23.4/AGENTPACKAGESTREMOTE.ZIP |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C505D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://a6dc35606b2c6816e.awsglobalaccelerator.com |
Source: AteraAgent.exe, 0000000C.00000000.1884188018.0000025DA9B72000.00000002.00000001.01000000.0000000F.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780001000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C21000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://acontrol.atera.com/ |
Source: rundll32.exe, 00000004.00000002.1861868953.0000000004AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780387000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780390000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805AF000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.0000000004405000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2046686892.00000242292AF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66BC000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E024543000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0244EB000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0244B9000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2176320463.000001951218C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://agent-api.atera.com |
Source: rundll32.exe, 00000004.00000002.1861868953.0000000004AA5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780387000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805AF000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.0000000004405000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2046686892.00000242292AF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66CF000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66BC000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E024543000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0244EB000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0244B9000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2176320463.000001951218C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://atera-agent-api-eu.westeurope.cloudapp.azure.com |
Source: AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/ |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr, 6cdf8b.msi.1.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F32AF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3729000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F3290000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2380145583.000001E7F2107000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED3B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000000.2271126671.0000000000645000.00000002.00000001.01000000.00000026.sdmp, Le55bnMCON.msi, SRUsb.exe.1.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr, 6cdf8b.msi.1.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED53000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB657F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt |
Source: AteraAgent.exe, 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924984962.0000025DC4373000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802A9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802F6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78029E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7806A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3692000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F3355000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F329E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE80A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE8B7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE903000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crtP |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crth |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3729000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED3B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE903000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED53000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C50FB000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C507B000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000000.2271126671.0000000000645000.00000002.00000001.01000000.00000026.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt |
Source: AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE8B7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt&D |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3772000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3729000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2047468417.00000242418E0000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2047468417.00000242418CF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED3B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5B1A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2348562257.000001E03CD39000.00000004.00000020.00020000.00000000.sdmp, cscript.exe, 0000001F.00000002.2198124194.000002ED7D54E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0 |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0 |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC401D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/ |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F32AF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3729000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F3290000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2380145583.000001E7F2107000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED3B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000000.2271126671.0000000000645000.00000002.00000001.01000000.00000026.sdmp, Le55bnMCON.msi, SRUsb.exe.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr, 6cdf8b.msi.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0 |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0= |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924984962.0000025DC435E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC4033000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC4006000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC401D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE80A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924984962.0000025DC4373000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802A9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802F6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78029E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7806A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3692000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780390000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F3355000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F329E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE80A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: AteraAgent.exe, 0000000C.00000002.1924984962.0000025DC434F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5B5B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlhttp://crl4.digicert.co |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3729000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED3B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE903000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C50FB000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C507B000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000000.2271126671.0000000000645000.00000002.00000001.01000000.00000026.sdmp, Le55bnMCON.msi | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC401D000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924984962.0000025DC4340000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: 6cdf8b.msi.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crlL |
Source: AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crlw |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr, 6cdf8b.msi.1.dr | String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02 |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3FD7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlche |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3FD7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com:80/DigiCertTrustedRootG4.crlLow |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC401D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/ |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr, 6cdf8b.msi.1.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE80A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB696A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB68CB000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB657F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC4033000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl$Y |
Source: AteraAgent.exe, 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924984962.0000025DC4373000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802A9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802F6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78029E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7806A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3692000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F3355000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F329E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE80A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE8B7000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE903000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl6 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl8 |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC4033000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlOXT6 |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC4033000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlfY?5 |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC4033000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlv |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlxw |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0= |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr, 6cdf8b.msi.1.dr | String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0 |
Source: AteraAgent.exe, 0000000C.00000002.1924984962.0000025DC4364000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlrlCache |
Source: AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5BD3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/ |
Source: AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5BFB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdowR7 |
Source: AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F3355000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en |
Source: AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabonK |
Source: AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE860000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5BFD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab4 |
Source: AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE860000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?15776c8 |
Source: AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE780000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3d47c1e |
Source: AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE780000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4d748c7 |
Source: AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5B5B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?64342e8 |
Source: AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5B5B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8ad9460 |
Source: AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5B5B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8d9e77f |
Source: AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE8F3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c6bf837 |
Source: AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5BFD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d935bcd |
Source: AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5BD3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f0390f1 |
Source: AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE780000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ff657aa |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cabS |
Source: AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE860000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cabY |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED3B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/vi |
Source: AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE7C9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/truste |
Source: AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE7C9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?81e1 |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8ad9 |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8d9e |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED20000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f039 |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C509F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://d17kmd0va0f0mp.cloudfront.net |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://d25btwd9wax8gu.cloudfront.net |
Source: AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000000.2022046349.0000024228672000.00000002.00000001.01000000.00000016.sdmp | String found in binary or memory: http://dl.google.com/googletalk/googletalk-setup.exe |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C509F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://download.splashtop.com |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3772000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://fedir.comsign.co.il/crl/ComSignCA.crl0 |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2189556505.000001952A592000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: http://james.newtonking.com/projects/json |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C505D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://my.splashtop.com |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: http://nlog-project.org/dummynamespace/ |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: http://nlog-project.org/ws/ |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: http://nlog-project.org/ws/3 |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: http://nlog-project.org/ws/5 |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverOneWayServer/ProcessLogMessages |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverServer/ProcessLogMessagesResponsep |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: http://nlog-project.org/ws/ILogReceiverServer/ProcessLogMessagesT |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: http://nlog-project.org/ws/T |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED53000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.dgi |
Source: AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE8B7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRMt |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3FD7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rh |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC401D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxX |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC401D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/l |
Source: AteraAgent.exe, 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924984962.0000025DC4373000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802A9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802F6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78029E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7806A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3692000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780390000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F3355000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F329E000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE80A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3772000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3729000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2047468417.00000242418E0000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2047468417.00000242418CF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED3B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5B1A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2348562257.000001E03CD39000.00000004.00000020.00020000.00000000.sdmp, cscript.exe, 0000001F.00000002.2198124194.000002ED7D54E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0A |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F32AF000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3729000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F3290000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2380145583.000001E7F2107000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED3B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000000.2271126671.0000000000645000.00000002.00000001.01000000.00000026.sdmp, Le55bnMCON.msi, SRUsb.exe.1.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr | String found in binary or memory: http://ocsp.digicert.com0K |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr | String found in binary or memory: http://ocsp.digicert.com0N |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr, 6cdf8b.msi.1.dr | String found in binary or memory: http://ocsp.digicert.com0O |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3729000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED3B000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE903000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED53000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C50FB000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C507B000.00000004.00000800.00020000.00000000.sdmp, PreVerCheck.exe, 00000027.00000000.2271126671.0000000000645000.00000002.00000001.01000000.00000026.sdmp | String found in binary or memory: http://ocsp.digicert.com0X |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED53000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://c |
Source: AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED53000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRS |
Source: AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE8B7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedRootG4.crt |
Source: AteraAgent.exe, 00000018.00000002.3107381795.0000019BCE8B7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedRootG4.crtit |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3FD7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com:80/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF |
Source: AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertAssuredIDRootCA.crl |
Source: AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3104741258.0000019BCE796000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.cr |
Source: AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3060869735.0000019BB5BFD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ps.atera.com |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780390000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB660B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6641000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66E9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66BC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB68CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ps.pndsn.com |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://repository.swisssign.com/0 |
Source: AteraAgent.exe, 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org |
Source: AteraAgent.exe, 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org/2004/07/ |
Source: AteraAgent.exe, 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.datacontract.org/2004/07/System.ServiceProcess |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: rundll32.exe, 00000004.00000002.1861868953.0000000004A84000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1861868953.00000000049E1000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780001000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.0000000004341000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.00000000043E4000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2046686892.0000024229203000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C21000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E02451B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0242F1000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C4F78000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2176320463.0000019511CFD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://sertifikati.ca.posta.rs/crl/PostaCARoot.crl0 |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr | String found in binary or memory: http://wixtoolset.org |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A18000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.00000000044E7000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.0000000004669000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.00000000041FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A18000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.00000000044E7000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.0000000004669000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.00000000041FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/news/ |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A18000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.00000000044E7000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.0000000004669000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.00000000041FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wixtoolset.org/releases/ |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2175576254.0000019511AF2000.00000002.00000001.01000000.0000001F.sdmp | String found in binary or memory: http://www.abit.com.tw/ |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.acabogacia.org/doc0 |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.anf.es/AC/RC/ocsp0c |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.ca.posta.rs/dokumentacija0h |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3772000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.certplus.com/CRL/class2.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.datev.de/zertifikat-policy-bt0 |
Source: AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F32C6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.datev.de/zertifikat-policy-int0 |
Source: AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F32C6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.datev.de/zertifikat-policy-std0 |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802F6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780390000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB696A000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB68CB000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB657F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000C.00000002.1924984962.0000025DC4373000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802A9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7802F6000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78029E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7806A4000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F3692000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F3355000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2384334256.000001E7F329E000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPSoSsr |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.digicert.com/CPStopS |
Source: AteraAgent.exe, 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2396363552.000001E7F3B50000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.e-trust.be/CPS/QNcerts |
Source: 6cdf8b.msi.1.dr | String found in binary or memory: http://www.flexerasoftware.com0 |
Source: AteraAgent.exe, 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.o |
Source: AteraAgent.exe, 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.oh |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E024589000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.P |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E02451B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.P2~ |
Source: rundll32.exe, 00000004.00000002.1861868953.0000000004A84000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.aterD |
Source: rundll32.exe, 00000010.00000002.1981482959.00000000043E4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.aterDf |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A18000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1861868953.0000000004A84000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1861868953.00000000049E1000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.00000000044E7000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.0000000004669000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780001000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.0000000004341000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.00000000043E4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.00000000041FA000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2046686892.0000024229203000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C21000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5D3E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66E9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66BC000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0244EB000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0244B9000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E02451B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0242F1000.00000004.00000800.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2176320463.0000019511CFD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A18000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1861868953.0000000004A84000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1861868953.00000000049E1000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.00000000044E7000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.0000000004669000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.0000000004341000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.00000000043E4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.00000000041FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/ |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E024589000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Prh |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C21000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5D3E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Pro |
Source: AgentPackageAgentInformation.exe, 00000014.00000002.2046686892.0000024229203000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0244EB000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0244B9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A18000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1861868953.0000000004A84000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1861868953.00000000049E1000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.00000000044E7000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.0000000004669000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780387000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.0000000004341000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.00000000043E4000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.00000000041FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/ |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780387000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/Acknowl |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780387000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AcknowledgeCommands |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/Age |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB657F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/AgentStarting |
Source: AgentPackageAgentInformation.exe, 00000014.00000002.2046686892.0000024229203000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/CommandResult |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5D3E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66E9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetCommands |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6932000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetCommands) |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetEnvironmentStatus |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5D3E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetRecurringPackages |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB660B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/GetRecurringPackagesiChannelSubscribeRequest |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5D3E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/Trace |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E02451B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/ |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E02451B000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0242F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/dynamic-fields/script-based |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E024589000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/guiComm |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E024589000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E024383000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/guiCommandResult |
Source: AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0244EB000.00000004.00000800.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 0000001B.00000002.2331883603.000001E0244B9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/recurringCommandResult |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2176320463.0000019511CFD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/thresholds/fbcf2d79-fde9-446f-9db8-b915db64fdfb |
Source: rundll32.exe, 00000004.00000002.1861868953.0000000004A84000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.1861868953.00000000049E1000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.0000000004341000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.00000000043E4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/track-event |
Source: rundll32.exe, 00000004.00000002.1861868953.0000000004AC6000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.1981482959.0000000004426000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.com/Production/Agent/track-event; |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780387000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.comh |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.comh2 |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://agent-api.atera.comhBo |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED66000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet-core-applaunch? |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED66000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet-core-applaunch?You |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED66000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet/app-launch-failed |
Source: AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED66000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/dotnet/app-launch-failed&gui=trueShowing |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://crl.anf.es/AC/ANFServerCA.crl0 |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C5083000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://download.splashtop.com |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C5083000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C505D000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C507F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://download.splashtop.com/csrs/Splashtop_Streamer_Win_DEPLOY_INSTALLER_v3.7.2.3.exe |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2046463798.0000024229082000.00000002.00000001.01000000.00000019.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2930180120.00000278DD6F0000.00000002.00000001.01000000.0000002B.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2189556505.000001952A592000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: https://github.com/JamesNK/Newtonsoft.Json |
Source: Microsoft.Win32.TaskScheduler.dll0.24.dr | String found in binary or memory: https://github.com/dahall/taskscheduler |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/dotnet/corefx/tree/7601f4f6225089ffb291dc7d58293c7bbf5c5d4f |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/dotnet/corefx/tree/7601f4f6225089ffb291dc7d58293c7bbf5c5d4f8 |
Source: System.IO.FileSystem.Primitives.dll.1.dr, System.IO.IsolatedStorage.dll.1.dr, System.Security.Cryptography.Cng.dll.1.dr, System.Reflection.Emit.dll.1.dr | String found in binary or memory: https://github.com/dotnet/runtime |
Source: AteraAgent.exe, 0000000D.00000002.2395797543.000001E7F3A02000.00000002.00000001.01000000.00000029.sdmp | String found in binary or memory: https://github.com/icsharpcode/SharpZipLib |
Source: AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C5058000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C4F78000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://my.splashtop.com |
Source: AgentPackageSTRemote.exe, 00000021.00000000.2105794495.00000278C4622000.00000002.00000001.01000000.0000001A.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C4F78000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://my.splashtop.com/csrs/win |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2189398737.000001952A588000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: https://nlog-project.org/ |
Source: AteraAgent.exe, 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, AgentPackageMonitoring.exe, 00000023.00000000.2107240038.0000019511082000.00000002.00000001.01000000.0000001B.sdmp | String found in binary or memory: https://packagesstore.blob.core.windows.net/installers/BitDefender/rmm.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.ateH |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.ateHz |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/a |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/ag |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7803CA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAg |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7803B6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAge |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780340000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78019C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageAgentInformation/1.13/AgentPackageAgentI |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageMonitoring/0.40/AgentPackageMonitoring.z |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageSTRemote/2.3/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7803CA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagescrossplatform/AgentPackageSTRemote/2.3/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB65EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E14000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.Availability/0.16/Agent.Package.Availability.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780148000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801D8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB65EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.IotPoc/0.2/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB65EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E14000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageADRemote/6.0/AgentPackageADRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780340000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78019C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageAgentInformation/37.9/AgentPackageAgentInformation |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageHeartbeat/17.11/AgentPackageHeartbeat.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageInternalPoller/13.0/AgentPackageInternalPoller.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMarketplace/1.6/AgentPackageMarketplace.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780148000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7803CA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageMonitoring/37.8/AgentPackageMonitoring.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801D8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageNetworkDiscovery/13.0/AgentPackageNetworkDiscovery |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageOsUpdates/20.1/AgentPackageOsUpdates.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageProgramManagement/26.0/AgentPackageProgramManageme |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageRuntimeInstaller/1.5/AgentPackageRuntimeInstaller. |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7803CA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSTRemote/23.4/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageSystemTools/27.6/AgentPackageSystemTools.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageTaskScheduler/13.0/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageTicketing/13.0/AgentPackageTicketing.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageUpgradeAgent/27.1/AgentPackageUpgradeAgent.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesmac/AgentPackageWindowsUpdate/24.6/AgentPackageWindowsUpdate.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB65EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E14000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Availability/0.16/Agent.Package.Availability.z |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780148000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801D8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB65EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.IotPoc/0.2/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB65EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E14000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5D3E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/Agent.Package.Watchdog/1.7/Agent.Package.Watchdog.zip?TV4U36 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageADRemote/6.0/AgentPackageADRemote.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5D3E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageADRemote/6.0/AgentPackageADRemote.zip?TV4U36qfng |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780340000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78019C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageAgentInformation/37.9/AgentPackageAgentInformati |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageHeartbeat/17.14/AgentPackageHeartbeat.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageInternalPoller/23.8/AgentPackageInternalPoller.z |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMarketplace/1.6/AgentPackageMarketplace.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMoni |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780148000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.zip?TV4U3 |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7803CA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageMonitoring/37.8/AgentPackageMonitoring.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801D8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB65EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageNetworkDiscovery/23.9/AgentPackageNetworkDiscove |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageOsUpdates/20.1/AgentPackageOsUpdates.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageProgramManagement/26.0/AgentPackageProgramManage |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageRuntimeInstaller/1.6/AgentPackageRuntimeInstalle |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageST |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.zip?TV4U36qfn |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7803CA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSTRemote/23.4/AgentPackageSTRemote.ziph |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageSystemTools/27.6/AgentPackageSystemTools.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTaskScheduler/17.2/AgentPackageTaskScheduler. |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTaskScheduler/17.2/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTicketing/30.1/AgentPackageTicketing.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageTicketing/30.1/AgentPackageTicketing.zip?TV4U36q |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CD5000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageUpgradeAgent/27.2/AgentPackageUpgradeAgent.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackagesnet45/AgentPackageWindowsUpdate/24.6/AgentPackageWindowsUpdate.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB65EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E14000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.Availability/13.0/Agent.Package.Availability.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780148000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7801D8000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB65EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.IotPoc/13.0/Agent.Package.IotPoc.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB65EA000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E14000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/Agent.Package.Watchdog/13.0/Agent.Package.Watchdog.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageADRemote/1.2/AgentPackageADRemote.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780340000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78019C000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageAgentInformation/22.7/AgentPackageAgentInformation |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780148000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageHeartbeat/16.9 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageHeartbeat/16.9/AgentPackageHeartbeat.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageInternalPoller/15.9/AgentPackageInternalPoller.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageMarketplace/13.0/AgentPackageMarketplace.zip |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageMonitoring/22.0/AgentPackageMonitoriP |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780148000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageMonitoring/22.0/AgentPackageMonitoring.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageNetworkDiscovery/15.0/AgentPackageNetworkDiscovery |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageOsUpdates/1.0/AgentPackageOsUpdates.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageProgramManagement/15.5/AgentPackageProgramManageme |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageRuntimeInstaller/13.0/AgentPackageRuntimeInstaller |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageSTRemote/16.0/AgentPackageSTRemo0 |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageSTRemote/16.0/AgentPackageSTRemote.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageSystemTools/18.9/AgentPackageSystemTools.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5C7C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageTaskScheduler/13.1/AgentPackageTaskScheduler.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageTicketing/18.9/AgentPackageTicketing.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageUpgradeAgent/22.1/AgentPackageUpgradeAgent.zip |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/agentpackageswin/AgentPackageWindowsUpdate/18.3/AgentPackageWindowsUpdate.zip |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000000.2105794495.00000278C4622000.00000002.00000001.01000000.0000001A.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2855258449.00000278C4F78000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.atera.com/installers/splashtop/win/SplashtopStreamer.exe |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000000.2105794495.00000278C4622000.00000002.00000001.01000000.0000001A.sdmp | String found in binary or memory: https://ps.atera.com/installers/splashtop/win/SplashtopStreamer.exepUsers/Shared/Splashtop |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78054F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780390000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB667D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6667000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6683000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6641000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66E9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6854000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB68CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78054F000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E780390000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E7800FB000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB667D000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CA3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6667000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66F3000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6683000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB660B000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6641000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66E9000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66BC000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB696E000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6854000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB68CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E780390000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=2b173d0e-2550-4ff5-aea3-7f5355b2456b |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=3a251339-3e59-4c6b-ab71-e6bac82c5bc4 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6667000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=76f279a6-9657-4bc1-af29-5ad914073c8b |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=82f65192-35a6-4baa-b7c0-3ae6a38ca2c1 |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E7800FB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=8c4940d7-6468-4110-952b-b2cf796c4fd8 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5CA3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=8ea1cf17-bcfa-4bc8-ac90-b38d9f8529aa |
Source: AteraAgent.exe, 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/time/0?pnsdk=NET45CSharp6.13.0.0&requestid=deb5ed17-32ce-44ff-8808-09cab14ce0c0 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6667000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6641000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB68CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6641000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/presence/sub |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB660B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/presence/sub_k |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB660B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/presence/sub_key/sub-c-a02ceca8 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB68CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/presence/sub_key/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/channel/fbcf2d79 |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5D3E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/su |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB5D3E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/sub-c-a02ceca8-a958-11e5-bd8c- |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB66CF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/fbcf2d79-fde9-446f- |
Source: AteraAgent.exe, 00000018.00000002.3063168617.0000019BB68CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ps.pndsn.com/v2/subscribe/sub-c-a02ceca8-a958-11e5-bd8c-0619f8945a4f/fbcf2d79-fde9-446f-9db8 |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2187898705.000001952A442000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: https://system.data.sqlite.org/ |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188329818.000001952A4A4000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: https://system.data.sqlite.org/X |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2187898705.000001952A442000.00000002.00000001.01000000.00000022.sdmp | String found in binary or memory: https://urn.to/r/sds_see |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.anf.es/AC/ACTAS/789230 |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.anf.es/AC/ANFServerCA.crl0 |
Source: AteraAgent.exe, 0000000D.00000002.2391825905.000001E7F383E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.anf.es/address/)1(0& |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, Le55bnMCON.msi, 6cdf87.msi.1.dr, 6cdf8b.msi.1.dr | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.newtonsoft.com/json |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2189556505.000001952A592000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: https://www.newtonsoft.com/jsonschema |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2188718103.000001952A4B2000.00000002.00000001.01000000.00000023.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2189398737.000001952A588000.00000002.00000001.01000000.00000023.sdmp | String found in binary or memory: https://www.nuget.org/packages/NLog.Web.AspNetCore |
Source: rundll32.exe, 00000003.00000003.1809738097.0000000004A49000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1819796804.0000000004518000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000003.1864689254.000000000469A000.00000004.00000020.00020000.00000000.sdmp, AteraAgent.exe, 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000010.00000003.1928739816.000000000422B000.00000004.00000020.00020000.00000000.sdmp, AgentPackageAgentInformation.exe, 00000014.00000002.2046463798.0000024229082000.00000002.00000001.01000000.00000019.sdmp, AteraAgent.exe, 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, AgentPackageSTRemote.exe, 00000021.00000002.2930180120.00000278DD6F0000.00000002.00000001.01000000.0000002B.sdmp, AgentPackageMonitoring.exe, 00000023.00000002.2189556505.000001952A592000.00000002.00000001.01000000.00000024.sdmp | String found in binary or memory: https://www.nuget.org/packages/Newtonsoft.Json.Bson |
Source: PreVerCheck.exe, 00000027.00000000.2271126671.0000000000645000.00000002.00000001.01000000.00000026.sdmp | String found in binary or memory: https://www.openssl.org/H |
Source: AgentPackageMonitoring.exe | String found in binary or memory: https://www.sqlite.org/copyright.html |
Source: AgentPackageMonitoring.exe, 00000023.00000002.2223243014.00007FFDF16A4000.00000002.00000001.01000000.0000001C.sdmp | String found in binary or memory: https://www.sqlite.org/copyright.html2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_3_048A7678 | 4_3_048A7678 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_3_048A0040 | 4_3_048A0040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_3_046A50B8 | 5_3_046A50B8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_3_046A59A8 | 5_3_046A59A8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_3_046A4D68 | 5_3_046A4D68 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 12_2_00007FFD9B28C922 | 12_2_00007FFD9B28C922 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 12_2_00007FFD9B28BB76 | 12_2_00007FFD9B28BB76 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B281C0E | 13_2_00007FFD9B281C0E |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B27C9DD | 13_2_00007FFD9B27C9DD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B283890 | 13_2_00007FFD9B283890 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B27C930 | 13_2_00007FFD9B27C930 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B279013 | 13_2_00007FFD9B279013 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B27CE90 | 13_2_00007FFD9B27CE90 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B271CF0 | 13_2_00007FFD9B271CF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B269AF2 | 13_2_00007FFD9B269AF2 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B27CF78 | 13_2_00007FFD9B27CF78 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B4793BD | 13_2_00007FFD9B4793BD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B47E2FA | 13_2_00007FFD9B47E2FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B476935 | 13_2_00007FFD9B476935 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B47AC97 | 13_2_00007FFD9B47AC97 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B480FF0 | 13_2_00007FFD9B480FF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B481000 | 13_2_00007FFD9B481000 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B480EA6 | 13_2_00007FFD9B480EA6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B480F02 | 13_2_00007FFD9B480F02 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 13_2_00007FFD9B260C58 | 13_2_00007FFD9B260C58 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 16_3_0677EDC8 | 16_3_0677EDC8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 16_3_06857678 | 16_3_06857678 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 16_3_06850040 | 16_3_06850040 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B25FA94 | 20_2_00007FFD9B25FA94 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B2578D6 | 20_2_00007FFD9B2578D6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B2610C0 | 20_2_00007FFD9B2610C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B263FFA | 20_2_00007FFD9B263FFA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B258682 | 20_2_00007FFD9B258682 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B27047D | 20_2_00007FFD9B27047D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B2512FB | 20_2_00007FFD9B2512FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B25BDB0 | 20_2_00007FFD9B25BDB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 20_2_00007FFD9B2564A5 | 20_2_00007FFD9B2564A5 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 22_2_00007FFD9B2812FB | 22_2_00007FFD9B2812FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 24_2_00007FFD9B279EDF | 24_2_00007FFD9B279EDF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 24_2_00007FFD9B281D8B | 24_2_00007FFD9B281D8B |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 24_2_00007FFD9B280338 | 24_2_00007FFD9B280338 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Code function: 24_2_00007FFD9B27EA28 | 24_2_00007FFD9B27EA28 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B278956 | 27_2_00007FFD9B278956 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B28600B | 27_2_00007FFD9B28600B |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B27CE09 | 27_2_00007FFD9B27CE09 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B27FC5D | 27_2_00007FFD9B27FC5D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B2712FA | 27_2_00007FFD9B2712FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B2740F8 | 27_2_00007FFD9B2740F8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B271835 | 27_2_00007FFD9B271835 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B27465F | 27_2_00007FFD9B27465F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B2966B0 | 27_2_00007FFD9B2966B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B279702 | 27_2_00007FFD9B279702 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B282655 | 27_2_00007FFD9B282655 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B27C47F | 27_2_00007FFD9B27C47F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B285B31 | 27_2_00007FFD9B285B31 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B279F93 | 27_2_00007FFD9B279F93 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B279FBF | 27_2_00007FFD9B279FBF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B28D350 | 27_2_00007FFD9B28D350 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B27421A | 27_2_00007FFD9B27421A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B290098 | 27_2_00007FFD9B290098 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Code function: 27_2_00007FFD9B270730 | 27_2_00007FFD9B270730 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B2882FB | 33_2_00007FFD9B2882FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B2951C8 | 33_2_00007FFD9B2951C8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B283EFA | 33_2_00007FFD9B283EFA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B296F59 | 33_2_00007FFD9B296F59 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B2915FD | 33_2_00007FFD9B2915FD |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B2815FA | 33_2_00007FFD9B2815FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B298476 | 33_2_00007FFD9B298476 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B285C68 | 33_2_00007FFD9B285C68 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B29F1D3 | 33_2_00007FFD9B29F1D3 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B29F0C5 | 33_2_00007FFD9B29F0C5 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Code function: 33_2_00007FFD9B280838 | 33_2_00007FFD9B280838 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF158B880 | 35_2_00007FFDF158B880 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF16401E0 | 35_2_00007FFDF16401E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF16320E0 | 35_2_00007FFDF16320E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1636960 | 35_2_00007FFDF1636960 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15011B0 | 35_2_00007FFDF15011B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF156F1B0 | 35_2_00007FFDF156F1B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1599170 | 35_2_00007FFDF1599170 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF157F220 | 35_2_00007FFDF157F220 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1613200 | 35_2_00007FFDF1613200 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF16350F0 | 35_2_00007FFDF16350F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15293D0 | 35_2_00007FFDF15293D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF159B370 | 35_2_00007FFDF159B370 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15DF3E0 | 35_2_00007FFDF15DF3E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF150D284 | 35_2_00007FFDF150D284 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF150F340 | 35_2_00007FFDF150F340 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF159D350 | 35_2_00007FFDF159D350 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1515640 | 35_2_00007FFDF1515640 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF156B647 | 35_2_00007FFDF156B647 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF154F630 | 35_2_00007FFDF154F630 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF150D634 | 35_2_00007FFDF150D634 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15074B0 | 35_2_00007FFDF15074B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1503474 | 35_2_00007FFDF1503474 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF150955C | 35_2_00007FFDF150955C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF155F780 | 35_2_00007FFDF155F780 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF164F790 | 35_2_00007FFDF164F790 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF154D770 | 35_2_00007FFDF154D770 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1651840 | 35_2_00007FFDF1651840 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF151D830 | 35_2_00007FFDF151D830 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15F56D0 | 35_2_00007FFDF15F56D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15A1690 | 35_2_00007FFDF15A1690 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15A7720 | 35_2_00007FFDF15A7720 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15736E0 | 35_2_00007FFDF15736E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF156B9F0 | 35_2_00007FFDF156B9F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15618DA | 35_2_00007FFDF15618DA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF152D910 | 35_2_00007FFDF152D910 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1549BA0 | 35_2_00007FFDF1549BA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15EDB80 | 35_2_00007FFDF15EDB80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1643C20 | 35_2_00007FFDF1643C20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF152BBE0 | 35_2_00007FFDF152BBE0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1535AD0 | 35_2_00007FFDF1535AD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1539A60 | 35_2_00007FFDF1539A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15B7A60 | 35_2_00007FFDF15B7A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1567B30 | 35_2_00007FFDF1567B30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15A3AF0 | 35_2_00007FFDF15A3AF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1515E50 | 35_2_00007FFDF1515E50 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1533E10 | 35_2_00007FFDF1533E10 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15DDCC0 | 35_2_00007FFDF15DDCC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15EBCD0 | 35_2_00007FFDF15EBCD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15D7D20 | 35_2_00007FFDF15D7D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1549CF0 | 35_2_00007FFDF1549CF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF159FED0 | 35_2_00007FFDF159FED0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15B5EA0 | 35_2_00007FFDF15B5EA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15A7EA0 | 35_2_00007FFDF15A7EA0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1583EB0 | 35_2_00007FFDF1583EB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1507EC0 | 35_2_00007FFDF1507EC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1547E70 | 35_2_00007FFDF1547E70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1595F20 | 35_2_00007FFDF1595F20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1539F30 | 35_2_00007FFDF1539F30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1517F30 | 35_2_00007FFDF1517F30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF155FEF0 | 35_2_00007FFDF155FEF0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1572240 | 35_2_00007FFDF1572240 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15BC220 | 35_2_00007FFDF15BC220 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF159A0C0 | 35_2_00007FFDF159A0C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15A40A0 | 35_2_00007FFDF15A40A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF158C110 | 35_2_00007FFDF158C110 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15A22B0 | 35_2_00007FFDF15A22B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1520330 | 35_2_00007FFDF1520330 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1522310 | 35_2_00007FFDF1522310 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15C8310 | 35_2_00007FFDF15C8310 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15AA2F0 | 35_2_00007FFDF15AA2F0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF16205D0 | 35_2_00007FFDF16205D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15085D4 | 35_2_00007FFDF15085D4 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15BA5D0 | 35_2_00007FFDF15BA5D0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF163E5B0 | 35_2_00007FFDF163E5B0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15BE590 | 35_2_00007FFDF15BE590 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15E6590 | 35_2_00007FFDF15E6590 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1580600 | 35_2_00007FFDF1580600 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15144DC | 35_2_00007FFDF15144DC |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15664A0 | 35_2_00007FFDF15664A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1584550 | 35_2_00007FFDF1584550 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF150A524 | 35_2_00007FFDF150A524 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1550510 | 35_2_00007FFDF1550510 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF150E80C | 35_2_00007FFDF150E80C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF159A7E0 | 35_2_00007FFDF159A7E0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF163C680 | 35_2_00007FFDF163C680 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF151E720 | 35_2_00007FFDF151E720 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1512738 | 35_2_00007FFDF1512738 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF155E990 | 35_2_00007FFDF155E990 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1508A3C | 35_2_00007FFDF1508A3C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15588A0 | 35_2_00007FFDF15588A0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15028C0 | 35_2_00007FFDF15028C0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1518860 | 35_2_00007FFDF1518860 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15C6860 | 35_2_00007FFDF15C6860 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15F6910 | 35_2_00007FFDF15F6910 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1558B90 | 35_2_00007FFDF1558B90 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15ACC00 | 35_2_00007FFDF15ACC00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1526A80 | 35_2_00007FFDF1526A80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1548A60 | 35_2_00007FFDF1548A60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15CAA70 | 35_2_00007FFDF15CAA70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF157CB50 | 35_2_00007FFDF157CB50 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15EAB00 | 35_2_00007FFDF15EAB00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1504DB4 | 35_2_00007FFDF1504DB4 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF163CD60 | 35_2_00007FFDF163CD60 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1560E30 | 35_2_00007FFDF1560E30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1516CC0 | 35_2_00007FFDF1516CC0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF154ACD0 | 35_2_00007FFDF154ACD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1634C80 | 35_2_00007FFDF1634C80 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1586D20 | 35_2_00007FFDF1586D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1650D30 | 35_2_00007FFDF1650D30 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF15C8D20 | 35_2_00007FFDF15C8D20 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1574D00 | 35_2_00007FFDF1574D00 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF159EFD0 | 35_2_00007FFDF159EFD0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF154AFB0 | 35_2_00007FFDF154AFB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1512F8C | 35_2_00007FFDF1512F8C |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF1549020 | 35_2_00007FFDF1549020 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF150CEA8 | 35_2_00007FFDF150CEA8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFDF152CE70 | 35_2_00007FFDF152CE70 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B25ED6D | 35_2_00007FFD9B25ED6D |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B256039 | 35_2_00007FFD9B256039 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B25BD61 | 35_2_00007FFD9B25BD61 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B2594FA | 35_2_00007FFD9B2594FA |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B4732A6 | 35_2_00007FFD9B4732A6 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B47F088 | 35_2_00007FFD9B47F088 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B472558 | 35_2_00007FFD9B472558 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B4724E8 | 35_2_00007FFD9B4724E8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B5812CF | 35_2_00007FFD9B5812CF |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B583C71 | 35_2_00007FFD9B583C71 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B584D17 | 35_2_00007FFD9B584D17 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B5812FB | 35_2_00007FFD9B5812FB |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B580CB0 | 35_2_00007FFD9B580CB0 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B579505 | 35_2_00007FFD9B579505 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B644F88 | 35_2_00007FFD9B644F88 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B64346A | 35_2_00007FFD9B64346A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B64EDB8 | 35_2_00007FFD9B64EDB8 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B640B77 | 35_2_00007FFD9B640B77 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B658D7F | 35_2_00007FFD9B658D7F |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B7E6A67 | 35_2_00007FFD9B7E6A67 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B7F3A8A | 35_2_00007FFD9B7F3A8A |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B7E9C65 | 35_2_00007FFD9B7E9C65 |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Code function: 35_2_00007FFD9B7E04C9 | 35_2_00007FFD9B7E04C9 |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Le55bnMCON.msi" | |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding CAAC4898E5F21B8FF741540F3B0CAAB6 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIE0CD.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_7135531 2 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.GenerateAgentId | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIE39D.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_7136187 6 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiStart | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIF6F7.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_7141140 10 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ShouldContinueInstallation | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding CA6DBA366017891C5744CC4FCFEFE125 E Global\MSI0000 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\net.exe "NET" STOP AteraAgent | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 STOP AteraAgent | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "TaskKill.exe" /f /im AteraAgent.exe | |
Source: C:\Windows\SysWOW64\taskkill.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="shyam@telcoict.com.au" /CompanyId="22" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="21" /AccountId="0013z00002eDbtlAAC" /AgentId="fbcf2d79-fde9-446f-9db8-b915db64fdfb" | |
Source: unknown | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI1021.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_7147593 32 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiEnd | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" fbcf2d79-fde9-446f-9db8-b915db64fdfb "29190784-5aaf-4974-b188-2285218acd1a" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 0013z00002eDbtlAAC | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" fbcf2d79-fde9-446f-9db8-b915db64fdfb "7ca2a215-f328-4822-895f-4d13156421e8" agent-api.atera.com/Production 443 or8ixLi90Mf "identified" 0013z00002eDbtlAAC | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Windows\System32\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" fbcf2d79-fde9-446f-9db8-b915db64fdfb "96b12e79-6bed-4b62-b87d-6860669b7bcc" agent-api.atera.com/Production 443 or8ixLi90Mf "generalinfo fromGui" 0013z00002eDbtlAAC | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cscript.exe cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: unknown | Process created: C:\Windows\System32\sppsvc.exe C:\Windows\system32\sppsvc.exe | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe" fbcf2d79-fde9-446f-9db8-b915db64fdfb "d85a67d4-12c7-47c2-9a5a-d8a5311da246" agent-api.atera.com/Production 443 or8ixLi90Mf "install eyJSbW1Db2RlIjoiaFpDREZQaEs3NW1KIn0=" 0013z00002eDbtlAAC | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe" fbcf2d79-fde9-446f-9db8-b915db64fdfb "e32a6a23-e8d4-4e32-b68d-b03fd8f497a4" agent-api.atera.com/Production 443 or8ixLi90Mf "syncprofile" 0013z00002eDbtlAAC | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k smphost | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\Temp\SplashtopStreamer.exe "C:\Windows\TEMP\SplashtopStreamer.exe" prevercheck /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Process created: C:\Windows\Temp\unpack\PreVerCheck.exe "C:\Windows\Temp\unpack\PreVerCheck.exe" /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Process created: C:\Windows\SysWOW64\msiexec.exe msiexec /norestart /i "setup.msi" /qn /l*v "C:\Windows\TEMP\PreVer.log.txt" CA_EXTPATH=1 USERINFO="sec_opt=0,confirm_d=0,hidewindow=1" | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 4351DC68752ACF7C899C2675605CABA5 E Global\MSI0000 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{5B352F26-5120-4117-A109-DE650674E7DA} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{FA7BA938-024B-4129-BDD0-6B3FE9E5FB66} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{A0FCA55A-7CF7-49BE-8B56-A74C1EB44F5E} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{0ADF7E2D-4BB9-42AA-A569-94D9707C001C} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{860F9839-DA15-4056-88A7-841AD3A27997} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{4F3231D3-6D37-465A-BC13-63CD6FF9624B} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{03A40452-2F14-4152-BA66-B5287BBD5C9B} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{6C5ECAA2-1855-4FDF-894D-C85ACC1D9D7D} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{05F4BBFC-F955-4195-A522-A30DD645E32B} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{B23DA011-82C1-4020-8602-12398184AECF} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe /C "taskkill.exe /F /IM SRServer.exe /T" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding CAAC4898E5F21B8FF741540F3B0CAAB6 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding CA6DBA366017891C5744CC4FCFEFE125 E Global\MSI0000 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="shyam@telcoict.com.au" /CompanyId="22" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="21" /AccountId="0013z00002eDbtlAAC" /AgentId="fbcf2d79-fde9-446f-9db8-b915db64fdfb" | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 4351DC68752ACF7C899C2675605CABA5 E Global\MSI0000 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIE0CD.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_7135531 2 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.GenerateAgentId | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIE39D.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_7136187 6 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiStart | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIF6F7.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_7141140 10 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ShouldContinueInstallation | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI1021.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_7147593 32 AlphaControlAgentInstallation!AlphaControlAgentInstallation.CustomActions.ReportMsiEnd | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\net.exe "NET" STOP AteraAgent | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "TaskKill.exe" /f /im AteraAgent.exe | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 STOP AteraAgent | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" fbcf2d79-fde9-446f-9db8-b915db64fdfb "29190784-5aaf-4974-b188-2285218acd1a" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 0013z00002eDbtlAAC | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" fbcf2d79-fde9-446f-9db8-b915db64fdfb "7ca2a215-f328-4822-895f-4d13156421e8" agent-api.atera.com/Production 443 or8ixLi90Mf "identified" 0013z00002eDbtlAAC | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" fbcf2d79-fde9-446f-9db8-b915db64fdfb "96b12e79-6bed-4b62-b87d-6860669b7bcc" agent-api.atera.com/Production 443 or8ixLi90Mf "generalinfo fromGui" 0013z00002eDbtlAAC | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe" fbcf2d79-fde9-446f-9db8-b915db64fdfb "d85a67d4-12c7-47c2-9a5a-d8a5311da246" agent-api.atera.com/Production 443 or8ixLi90Mf "install eyJSbW1Db2RlIjoiaFpDREZQaEs3NW1KIn0=" 0013z00002eDbtlAAC | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe "C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe" fbcf2d79-fde9-446f-9db8-b915db64fdfb "e32a6a23-e8d4-4e32-b68d-b03fd8f497a4" agent-api.atera.com/Production 443 or8ixLi90Mf "syncprofile" 0013z00002eDbtlAAC | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\sc.exe "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\SysWOW64\msiexec.exe msiexec /norestart /i "setup.msi" /qn /l*v "C:\Windows\TEMP\PreVer.log.txt" CA_EXTPATH=1 USERINFO="sec_opt=0,confirm_d=0,hidewindow=1" | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{03A40452-2F14-4152-BA66-B5287BBD5C9B} | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cscript.exe cscript "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatus | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Process created: C:\Windows\Temp\SplashtopStreamer.exe "C:\Windows\TEMP\SplashtopStreamer.exe" prevercheck /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\SplashtopStreamer.exe | Process created: C:\Windows\Temp\unpack\PreVerCheck.exe "C:\Windows\Temp\unpack\PreVerCheck.exe" /s /i sec_opt=0,confirm_d=0,hidewindow=1 | |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Process created: C:\Windows\SysWOW64\msiexec.exe msiexec /norestart /i "setup.msi" /qn /l*v "C:\Windows\TEMP\PreVer.log.txt" CA_EXTPATH=1 USERINFO="sec_opt=0,confirm_d=0,hidewindow=1" | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{5B352F26-5120-4117-A109-DE650674E7DA} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{FA7BA938-024B-4129-BDD0-6B3FE9E5FB66} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{A0FCA55A-7CF7-49BE-8B56-A74C1EB44F5E} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{0ADF7E2D-4BB9-42AA-A569-94D9707C001C} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{860F9839-DA15-4056-88A7-841AD3A27997} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{4F3231D3-6D37-465A-BC13-63CD6FF9624B} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{03A40452-2F14-4152-BA66-B5287BBD5C9B} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{6C5ECAA2-1855-4FDF-894D-C85ACC1D9D7D} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{05F4BBFC-F955-4195-A522-A30DD645E32B} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{B23DA011-82C1-4020-8602-12398184AECF} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe /C "taskkill.exe /F /IM SRServer.exe /T" | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{FA7BA938-024B-4129-BDD0-6B3FE9E5FB66} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe C:\Windows\TEMP\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isA4D9.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{05F4BBFC-F955-4195-A522-A30DD645E32B} | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msihnd.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srclient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: spp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vssapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vsstrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: riched20.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: usp10.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msls31.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: edputil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wintypes.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: appresolver.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: bcp47langs.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: slc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sppc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: propsys.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: edputil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wintypes.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: appresolver.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: bcp47langs.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: slc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: sppc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Section loaded: webio.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: amsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: userenv.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wscapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: netutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wtsapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winsta.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: devobj.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: napinsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: wshbth.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: nlaapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: cryptnet.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\System32\cscript.exe | Section loaded: wbemcomn.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: wldp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: profapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: rasapi32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: rasman.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: rtutils.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: schannel.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: smphost.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: mispace.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: sxshared.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wmiclnt.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: devobj.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wevtapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: virtdisk.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: bcd.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: fltlib.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: cscapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: fmifs.dll | |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\.version | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.runtimeconfig.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.NETCore.App.deps.json | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Directory created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI2FB3.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PkgHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppAnnotation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.UserSecrets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\WBAppVidRec.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x86.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIF6F7.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRManager.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI4908.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\dbghelp.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.FileExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\my_setup.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSelfSignCertUtil.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\avutil-55.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Atera.Agent.Package.Infrastructure.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppBrowser.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIF6F7.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI5BB6.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI1021.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\legacy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\64bits\stgamepad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomCtrl32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDetect.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVirtualDisplay.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIF6F7.tmp | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIE0CD.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI1021.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiCaptor.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\64bits\stvad.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE0CD.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcelt-0.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIE39D.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsbVhciCtrl64.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIF6F7.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUACCheck.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Security.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIE0CD.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI1021.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x64\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcrypto-3.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileProviders.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\Mirror2Extend.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\it\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIE39D.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libx264-116.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\ARPPRODUCTICON.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Atera.Agent.Package.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIF91C.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stvideo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.CommandLine.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE39D.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppBS.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI6D7A.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libmp4v2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppED.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Polly.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperExx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppPB.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\PrnPort.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Dapper.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\qrcodelib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\fr\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsb.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI15A2.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x64\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SROpus.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\64bits\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264Wrapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIF96B.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\32bits\stvad.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\de\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\swresample-2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI1021.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRApp.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\sthid.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\hidkmdf.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIE0CD.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrlEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\setupdrv.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.EnvironmentVariables.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\32bits\stvspk.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\LiteDB.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\hidkmdf.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\AgentPackageADRemote.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Agent.Package.Watchdog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK_x86.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\64bits\stvspk.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\32bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\SetupUtil.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsbVhciCtrl32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\CliWrap.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.WebSockets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.UnmanagedMemoryStream.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Binder.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSI1021.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppCam.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordbi.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppFileHound.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.UnmanagedMemoryStream.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebProxy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.DataContractSerialization.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIE0CD.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAgent.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\StructureMap.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceProcess.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.Reader.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAdemWrapper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAudioChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.ThreadPool.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Elevator.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\ucrtbase.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\dbgshim.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Globalization.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\NvFBC.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIA212.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileProviders.Physical.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PinShortCut.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x64\SRWacomUtil64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcurl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIBD8C.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\sthid.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Agent.Package.Watchdog.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.InteropServices.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.EventBasedAsync.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorlib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Resources.ResourceManager.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdateInstall.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUtility.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Overlapped.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.CompilerServices.VisualC.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeatMini.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIA408.tmp | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIE39D.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.TypeConverter.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.HttpUtility.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomUtil32.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.DependencyInjection.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdwmark.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Data.SQLite.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-math-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.DependencyInjection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsb.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Polly.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\fips.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIFA66.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\setupdrv.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Configuration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\WdfCoInstaller01009.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Expressions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\es\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.ReaderWriter.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.AccessControl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Expressions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XPath.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\choco.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\stgamepad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIA2DE.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Mail.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\msquic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAudioResample.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x86\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Cng.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\WdfCoInstaller01009.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscorrc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.Lightweight.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\amf-vcedem-win32.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIE39D.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stvideo.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Pubnub.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x64\SRWacomCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdwmark.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\OpenHardwareMonitorLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | File created: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.WebHeaderCollection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | File created: C:\Windows\Installer\MSIF6F7.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOGPFAULTERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\CredentialManagement.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.HttpListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\PkgHelper.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI2FB3.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.X509Certificates.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppAnnotation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\AgentPackageRuntimeInstaller.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\AgentPackageUpgradeAgent.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Interop.WUApiLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.UserSecrets.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Encoding.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stmirror.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Data.SQLite.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\log4net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Contracts.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.Concurrent.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.OpenSsl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.CSharp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\WBAppVidRec.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encoding.CodePages.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x86.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF6F7.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.ThreadPool.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRManager.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.FileExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI4908.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\my_setup.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.WebSockets.Client.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperEx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{05510FEB-0C18-4F43-B58E-B2F6AABA3CF6}\ISRT.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSelfSignCertUtil.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\AgentPackageInternalPoller.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Dataflow.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiHelper.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\avutil-55.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\win\lib\net6.0\System.Diagnostics.EventLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Atera.Agent.Package.Infrastructure.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppBrowser.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.Windows.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF6F7.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Csp.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Diagnostics.EventLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Globalization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI5BB6.tmp | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI1021.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Sockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Algorithms.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingTrayTMP.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\legacy.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Core.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Options.ConfigurationExtensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.ILGeneration.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.ServiceProcess.ServiceController.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.CompilerServices.VisualC.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\EvtLogProvider\stevt_srs_x64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Formatters.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\64bits\stgamepad.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Console.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Process.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\my_setup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Wacom\x86\SRWacomCtrl32.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDetect.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Numerics.Vectors.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVirtualDisplay.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Microsoft.Win32.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF6F7.tmp | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE0CD.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUpdate.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\stprintmon.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{FEBDD9EF-BE90-4DAE-82FA-DBB25B423142}\ISRT.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Data.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI1021.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp64\driver\mv2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileSystemGlobbing.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.EventLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingNotifications.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRDxgiCaptor.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.TextWriterTraceListener.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Compression.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stmirror.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\Atera.AgentCommunication.Models.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\64bits\stvad.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.DataAnnotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\enum.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE0CD.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE39D.tmp-\Microsoft.Deployment.WindowsInstaller.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcelt-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsbVhciCtrl64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XDocument.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Http.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF6F7.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Hosting.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRUACCheck.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Globalization.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.Queryable.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebClient.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\GamePad\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\hostpolicy.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.Utils.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\XDColMan.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Security.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE0CD.tmp-\AlphaControlAgentInstallation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Immutable.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI1021.tmp-\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.StackTrace.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.AppContext.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x64\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Text.RegularExpressions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libcrypto-3.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.FileProviders.Abstractions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\Mirror2Extend.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.TypeExtensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\it\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\AgentPackageHeartbeat.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.Sinks.File.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\WindowsBase.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\xp\driver\mv2.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE39D.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Handles.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\pl\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XmlDocument.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.Exceptions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingPackageExtensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\System.Buffers.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\StructureMap.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libx264-116.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\netstandard.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.Cryptography.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\ARPPRODUCTICON.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Tasks.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Atera.Agent.Package.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Handles.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\zh-Hant\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Process.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\browser\lib\net6.0\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebSockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\t2tWinFormAppBarLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.NetworkInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\AgentPackageMarketplace.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\createdump.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{05510FEB-0C18-4F43-B58E-B2F6AABA3CF6}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\NLog.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF91C.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.DriveInfo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\win\lib\net6.0\System.Diagnostics.EventLog.Messages.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Resources.Writer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.MemoryMappedFiles.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Numerics.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.InteropServices.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Tasks.Parallel.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\system32\SRCredentialProvider.dll (copy) | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Console.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XPath.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.EventSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\stvideo.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Metadata.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.IsolatedStorage.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\BouncyCastle.Crypto.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.VisualBasic.Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.CommandLine.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Reflection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE39D.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Http.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdwmark.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Text.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppBS.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{B9BAB4A5-0A56-4A86-B2CC-F9AF047FA00F}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI6D7A.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libmp4v2.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Text.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\plugin\SRAppED.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\StructureMap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\NLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Polly.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.InteropServices.RuntimeInformation.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\utils\devcon.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.Utils.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.WebHeaderCollection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.NameResolution.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Primitives.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Hosting.Abstractions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\QRCoder.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.AccessControl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264WrapperExx.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxywddm.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\64bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\utils\DIFxCmd64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRAppPB.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRChat.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.DiaSymReader.Native.amd64.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Extensions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Win32.TaskScheduler.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Claims.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Thread.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\utils\PrnPort.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x86\lci_iddcx.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.Utils.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Serilog.Extensions.Hosting.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdbook.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\utils\devcon64.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Memory.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Microsoft.ApplicationInsights.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.ZipFile.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Buffers.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Requests.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Threading.Channels.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.IsolatedStorage.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Dapper.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.Console.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\CredentialManagement.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Security.SecureString.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Transactions.Local.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\IdleTimeFinder.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\utils\DIFxCmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\fr\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Formats.Asn1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\qrcodelib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\xdscale.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Collections.Specialized.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x64\SRUsb.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI15A2.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-console-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\Microsoft.Win32.Registry.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\libssl-3.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Polly.dll | Jump to dropped file |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Dropped PE file which has not been started: C:\Windows\Temp\unpack\libssl-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Pipes.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\CredProvider\x64\SRCredentialProvider.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.Debug.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Net.Quic.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\win10\64bits\XDColMan.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Tracing.dll | Jump to dropped file |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Dropped PE file which has not been started: C:\Windows\Temp\unpack\SRSocketCtrl.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ComponentModel.Annotations.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.Emit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Drawing.Primitives.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SROpus.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Serialization.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\System.Text.Encodings.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Security.Principal.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{111B374A-FF4E-4B16-87C0-18762C80C5C7}\ISRT.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clrjit.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Monitor\64bits\stdpms.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRx264Wrapper.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\CommunityToolkit.WinUI.Notifications.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Xml.XmlSerializer.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIF96B.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.Ping.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Intrinsics.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\Microsoft.Win32.TaskScheduler.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\AgentPackageProgramManagement.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.Serialization.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Xml.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win10\32bits\stvad.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore_amd64_amd64_6.0.3524.45918.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\de\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\swresample-2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.DispatchProxy.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Polly.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.Abstractions.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\CredentialManagement.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.MemoryMappedFiles.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.TraceSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Dynamic.Runtime.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVideo\64bits\stvideo.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\RunScriptAsUser.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\System.Management.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRApp.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI1021.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.FileSystem.Watcher.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\sthid.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\runtimes\win\lib\net6.0\System.ServiceProcess.ServiceController.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\64bits\hidkmdf.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Runtime.Extensions.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win10\x64\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\NLog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.Native.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE0CD.tmp-\System.Management.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\x86\SQLite.Interop.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRVideoCtrlEx.dll | Jump to dropped file |
Source: C:\Windows\Temp\unpack\PreVerCheck.exe | Dropped PE file which has not been started: C:\Windows\Temp\unpack\libcrypto-3.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\setupdrv.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.EnvironmentVariables.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\System32\SRC92E.tmp | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\System.Memory.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Web.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\vista64\driver\mv2.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\clretwrc.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\Atera.AgentPackages.CommonLib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\32bits\stvspk.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\LiteDB.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Options.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Temp\{FEBDD9EF-BE90-4DAE-82FA-DBB25B423142}\_isres_0x0409.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Private.Xml.Linq.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ObjectModel.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.Tools.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.ServiceModel.Web.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\ru\Microsoft.Win32.TaskScheduler.resources.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\LciDisplay\win7\x86\lci_proxyumd32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\VirtualDriver\hidkmdf.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Agent.Package.Watchdog.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\AgentPackageADRemote.exe | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.ComponentModel.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Logging.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\BdEpSDK_x86.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVSpk\64bits\stvspk.sys | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Diagnostics.StackTrace.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVAD\win7\32bits\stvad.sys | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Support\SetupUtil.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Runtime.Serialization.Xml.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackage.Common.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdnup.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.Compression.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STVirtualUSB\SRUsb\x86\SRUsbVhciCtrl32.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Collections.NonGeneric.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Threading.Overlapped.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\CliWrap.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\Newtonsoft.Json.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\stprintmon.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\ICSharpCode.SharpZipLib.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.Net.WebSockets.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\AgentPackageTicketing.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.Reflection.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\System.IO.FileSystem.AccessControl.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\Mirror\utils\devcon64.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\System.ValueTuple.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\System.IO.UnmanagedMemoryStream.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\System.Diagnostics.DiagnosticSource.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.35\mscordaccore.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\Agent.Package.Watchdog\Microsoft.Extensions.Configuration.Binder.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\32bits\xdsmplui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\Driver\STPrinter\64bits\xdbook.dll | Jump to dropped file |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe | Dropped PE file which has not been started: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\System.Runtime.CompilerServices.Unsafe.dll | Jump to dropped file |
Source: C:\Windows\SysWOW64\rundll32.exe TID: 1800 | Thread sleep time: -30000s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7116 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1700 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1696 | Thread sleep count: 3655 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 1696 | Thread sleep count: 6057 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7320 | Thread sleep time: -27670116110564310s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7320 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7352 | Thread sleep time: -150000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7364 | Thread sleep time: -5534023222112862s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7348 | Thread sleep time: -180000s >= -30000s | |
Source: C:\Windows\SysWOW64\rundll32.exe TID: 7416 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7736 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7712 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7820 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7872 | Thread sleep count: 9038 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7864 | Thread sleep count: 371 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 5516 | Thread sleep count: 36 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 5516 | Thread sleep time: -33204139332677172s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7220 | Thread sleep time: -60000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 404 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe TID: 7184 | Thread sleep time: -90000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 8140 | Thread sleep count: 6522 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 8144 | Thread sleep count: 2620 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep count: 33 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -30437127721620741s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -599875s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -599765s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -599656s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -599547s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -599437s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -599328s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -599217s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -599109s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -599000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -598890s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -598781s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -598672s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -598561s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -598453s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -598344s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -598229s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -598109s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -597996s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -597547s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -597234s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -597125s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -597015s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -596906s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -596787s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -596665s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -596543s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -596436s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -596315s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -596187s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -596078s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -595969s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -595844s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -595734s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -595625s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -595515s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -595406s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -595297s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7100 | Thread sleep time: -595187s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe TID: 7288 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep count: 37 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -34126476536362649s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 1076 | Thread sleep count: 6673 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -599859s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -599746s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -599639s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -599529s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -599398s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -599265s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -599109s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -598738s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -598358s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -598220s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -598093s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -597967s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -597859s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -597702s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -597584s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -597453s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -597244s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -597129s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 1076 | Thread sleep count: 3017 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -596979s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -596842s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -596729s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -596624s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -596515s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -596400s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -596295s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -596187s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -596077s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -595968s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -595856s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -595714s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -595559s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -595449s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -595331s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -595212s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -595093s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -594963s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -594843s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -594734s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -594624s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -594515s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -594405s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -594296s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -594187s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -594078s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -593968s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -593859s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -593750s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -593640s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -593527s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -593421s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -593312s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -593202s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -593093s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -592984s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -592874s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -592765s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe TID: 7400 | Thread sleep time: -592656s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 3796 | Thread sleep count: 3217 > 30 | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 5304 | Thread sleep time: -7378697629483816s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 5304 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 6584 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe TID: 2792 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Windows\Temp\SplashtopStreamer.exe TID: 5344 | Thread sleep time: -60000s >= -30000s | |
Source: C:\Windows\SysWOW64\msiexec.exe TID: 7332 | Thread sleep time: -60000s >= -30000s | |
Source: Yara match | File source: 20.2.AgentPackageAgentInformation.exe.24228f90000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 35.2.AgentPackageMonitoring.exe.19511510000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 12.0.AteraAgent.exe.25da9b70000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 33.0.AgentPackageSTRemote.exe.278c4620000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 20.0.AgentPackageAgentInformation.exe.24228670000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 35.0.AgentPackageMonitoring.exe.19511080000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000018.00000002.3058266535.0000019BB5444000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2850032441.00000278C4821000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1923621881.0000025DAB86C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2386760973.000001E7F3650000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3058266535.0000019BB543E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2382135962.000001E7F2370000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2045666683.00000242288C0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2190585524.000001952AF77000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2069210697.0000024AD707B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1923621881.0000025DAB7B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2172224977.0000019511170000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000002.1981482959.0000000004341000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2391825905.000001E7F3794000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2935696263.00000278DD7D3000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E78006E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2173998714.0000019511512000.00000002.00000001.01000000.0000001D.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2047468417.0000024241840000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2172506342.0000019511251000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2045722726.0000024228935000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1924284253.0000025DC4033000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000000.2022046349.0000024228672000.00000002.00000001.01000000.00000016.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2331883603.000001E0244E8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2069210697.0000024AD7040000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1923621881.0000025DAB7A2000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1922775108.0000025DA9C80000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2328116682.000001E023B00000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2397705041.000001E7F3B7F000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2850032441.00000278C482D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2855258449.00000278C5083000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2347191347.000001E03CC27000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2172506342.00000195112FB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1923621881.0000025DAB7A4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1923621881.0000025DAB77C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2046686892.0000024229181000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2190647233.000001952B175000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1924284253.0000025DC3F50000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2330427171.000001E023C20000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2935696263.00000278DD80D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3104741258.0000019BCE7C9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1924284253.0000025DC401D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2223066667.00007FFDF1699000.00000004.00000001.01000000.0000001C.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB6921000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2191541804.000001952B2FE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3109272217.0000019BCED66000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2046686892.00000242291F3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2328116682.000001E023B09000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.1861868953.0000000004A84000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2331883603.000001E0244EB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2380145583.000001E7F211E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2205414780.000001C5C146C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3104741258.0000019BCE796000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E7801DC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2386760973.000001E7F36D3000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2850032441.00000278C4805000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E7803CA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3104741258.0000019BCE80A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB692E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2045722726.000002422896E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1923621881.0000025DAB779000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E7802A9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB6936000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2380145583.000001E7F20E0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2071640791.0000024AD7813000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1922878127.0000025DA9CC0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2328116682.000001E023B1C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2205414780.000001C5C1460000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB696A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2380145583.000001E7F216D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3060869735.0000019BB5B1A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3058266535.0000019BB5400000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2331883603.000001E0244AC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E7802F6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2205875034.000001C5C1560000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2855258449.00000278C510C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB690D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2071640791.0000024AD7803000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2331883603.000001E024517000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2331883603.000001E024383000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E78029E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2362532887.00000028B39E5000.00000004.00000010.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2172506342.000001951121C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2172506342.000001951125C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3053597971.00000077A94F5000.00000004.00000010.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2071640791.0000024AD7791000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2069210697.0000024AD7049000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000026.00000002.2834835376.00000000005A0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2069210697.0000024AD70C9000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2386760973.000001E7F3729000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB660B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E780387000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.1861868953.00000000049E1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2172506342.000001951129A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1926114762.00007FFD9B314000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2328116682.000001E023B46000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3058266535.0000019BB548D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000016.00000002.2071607928.0000024AD73F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB6641000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3058027319.0000019BB52C0000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3104741258.0000019BCE7B3000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1923621881.0000025DAB7AA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000000.2105794495.00000278C4622000.00000002.00000001.01000000.0000001A.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2386760973.000001E7F3692000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB66CF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1923621881.0000025DAB822000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB66BC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000026.00000002.2833474219.00000000004C0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3104741258.0000019BCE780000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2396363552.000001E7F3AF0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2850032441.00000278C48C4000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2045722726.00000242288E0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000002.1981482959.00000000043E4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2391825905.000001E7F3782000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2174197330.0000019511530000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB692A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB6722000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000003.2082753921.000001C5C1580000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E780390000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2328116682.000001E023B3C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB5C21000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3104741258.0000019BCE838000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2328116682.000001E023B84000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3109272217.0000019BCED6D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2191385824.000001952B186000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2935696263.00000278DD7A0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001F.00000002.2197804094.000002ED7D4D0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB5D3E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3109272217.0000019BCED79000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2331883603.000001E024589000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2331883603.000001E024453000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2172506342.0000019511210000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000000.1884188018.0000025DA9B72000.00000002.00000001.01000000.0000000F.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2345160443.000001E03CB80000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000000.2107240038.0000019511082000.00000002.00000001.01000000.0000001B.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3060664134.0000019BB5600000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2384334256.000001E7F32C6000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2331883603.000001E0244B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1922964501.0000025DA9CE1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E780148000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2046686892.0000024229203000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E78042A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000003.1819796804.00000000044E7000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000005.00000003.1864689254.0000000004669000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2046334309.0000024228F92000.00000002.00000001.01000000.00000018.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2185856294.000001952A2D0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1923212837.0000025DA9D76000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB5C88000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2384334256.000001E7F3355000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1923621881.0000025DAB6F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2331883603.000001E02451B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000014.00000002.2045722726.0000024228920000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1922878127.0000025DA9CCC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2347851397.000001E03CC80000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2855258449.00000278C4F01000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1924960432.0000025DC4240000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E78028C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3108402911.0000019BCE930000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2381864614.000001E7F21E0000.00000004.00000020.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2852316069.00000278C4A30000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001D.00000002.2205414780.000001C5C1483000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2850032441.00000278C486D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000003.1809738097.0000000004A18000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB6854000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3109272217.0000019BCED53000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1922964501.0000025DA9CED000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB657F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB68CB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.1925310996.0000025DC43AA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E7805E3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3060869735.0000019BB5BFD000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2176320463.0000019511C11000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000003.1928739816.00000000041FA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E780001000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2850032441.00000278C47E0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000021.00000002.2855258449.00000278C4F78000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E780340000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000D.00000002.2364755560.000001E78042D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3060869735.0000019BB5B5B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2176320463.00000195121BB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000001B.00000002.2331883603.000001E0242F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000018.00000002.3063168617.0000019BB5E24000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000023.00000002.2176320463.0000019511CFD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 6196, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 3264, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 6484, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 2288, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 7140, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: rundll32.exe PID: 7272, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 7660, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 7768, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AteraAgent.exe PID: 7824, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageAgentInformation.exe PID: 7980, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: cmd.exe PID: 8112, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: cscript.exe PID: 8180, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageSTRemote.exe PID: 7092, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: AgentPackageMonitoring.exe PID: 4108, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: SplashtopStreamer.exe PID: 1016, type: MEMORYSTR |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.InstallLog, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSI1021.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackage.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\Atera.AgentPackages.CommonLib.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFC4F3156EFB829EDF.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.ModelsV3.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\UserDetections.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF87B49D07C30BE433.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\AgentPackageProgramManagement.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\Microsoft_.NET_Runtime_-_6.0.35_(x64)_20241108075552_000_dotnet_runtime_6.0.35_win_x64.msi.log, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF0B1F83CB212A9075.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\AteraAgent.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF761CCED7FD57F589.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\AgentPackageUpgradeAgent.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\Atera.AgentPackages.ModelsV3.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFD8DCFFD735C6E6BF.TMP, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIF6F7.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF34C6AB6AD4D1677B.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\AgentPackageADRemote.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DFD7CE1361C4B2B636.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\AgentPackageInternalPoller.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\Atera.AgentPackages.CommonLib.dll, type: DROPPED |
Source: Yara match | File source: C:\Config.Msi\6cdf86.rbs, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\TicketingPackageExtensions.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIF90B.tmp, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIE0CD.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\RestartReminder.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\inprogressinstallinfo.ipi, type: DROPPED |
Source: Yara match | File source: C:\Windows\Installer\MSIE39D.tmp-\AlphaControlAgentInstallation.dll, type: DROPPED |
Source: Yara match | File source: C:\Windows\System32\InstallUtil.InstallLog, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageTicketing\AgentPackageTicketing.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\AgentPackageRuntimeInstaller.exe, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageOsUpdates\AgentPackageOsUpdates.Common.dll, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\AgentPackageSystemTools.exe, type: DROPPED |
Source: Yara match | File source: C:\Windows\Temp\~DF9E3106EBFEFF2114.TMP, type: DROPPED |
Source: Yara match | File source: C:\Program Files (x86)\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe, type: DROPPED |