Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: rapeflowwj.lat |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: crosshuaht.lat |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: sustainskelet.lat |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: aspecteirs.lat |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: energyaffai.lat |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: necklacebudi.lat |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: discokeyus.lat |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: grannyejh.lat |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: crayonutteh.click |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: lid=%s&j=%s&ver=4.0 |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: TeslaBrowser/5.5 |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: - Screen Resoluton: |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: - Physical Installed Memory: |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: Workgroup: - |
Source: 7.2.powershell.exe.400000.0.raw.unpack |
String decryptor: yJaNLj--re2 |
Source: |
Binary string: api-ms-win-crt-locale-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-runtime-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\codebar\Desktop\Dev\Git\iMazing3-Win\Submodules\DevKit-Win\DevKit\obj\Release\net462\DevKit.pdbSHA256 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\Macmade\Desktop\iMazing-Win\hotfix\Submodules\DDNA-AppCache\tmp\iMazing-Converter\Build\Release\Products\win64\HEIC_SWIG_DLL_v142.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-file-l1-2-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-console-l1-2-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-memory-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: d:\source\HTML-Renderer\Source\HtmlRenderer\obj\Release\HtmlRenderer.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-debug-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: d:\source\github\HTML-Renderer\Source\HtmlRenderer.PdfSharp\obj\Release\HtmlRenderer.PdfSharp.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\Macmade\Desktop\Build\DDNA-BuildCache\master\tmp\gpod\Build\64\Release\gpod.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\NetSparkle\NetSparkle\src\NetSparkle\obj\Release\net452\NetSparkle.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\codebar\Desktop\Dev\Git\iMazing3-Win\DDNAToolKit\IDE\VisualStudio\DDNAInterop\obj\x64\Release\net462\DDNAInterop.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-sysinfo-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-filesystem-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: protobuf-net.pdbSHA256}Lq source: powershell.exe, 00000005.00000002.7041071447.0000000007980000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-stdio-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\1\s\SDK\AppCenter\Microsoft.AppCenter.WindowsDesktop\obj\Microsoft.AppCenter.WindowsDesktop\Release\net462\Microsoft.AppCenter.pdbSHA2564 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: protobuf-net.pdb source: powershell.exe, 00000005.00000002.7041071447.0000000007980000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: C:\Users\codebar\Desktop\Dev\Git\iMazing3-Win\DDNAToolKit\IDE\VisualStudio\DDNAInterop\obj\x64\Release\net462\DDNAInterop.pdbSHA256 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\_work\1\s\third_party\edge_webview2\win\winforms_control\Microsoft.Web.WebView2.WinForms\obj\release\net45\Microsoft.Web.WebView2.WinForms.pdbP source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: d:\agent\_work\2\s\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\Macmade\Desktop\iMazing-Win\hotfix\Submodules\DDNA-AppCache\tmp\iMazing-Profile-Editor-Win\Submodules\Manifest-Operations\Manifest-Operations-Shared\obj\Release\net462\Manifest-Operations-Shared.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-heap-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-util-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\DDNA\ColorSet\ColorSetKit\obj\Release\net462\ColorSetKit.pdbSHA256m source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-synch-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-environment-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\_work\1\s\third_party\edge_webview2\win\wpf_control\Microsoft.Web.WebView2.Wpf\obj\release\net45\Microsoft.Web.WebView2.Wpf.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-errorhandling-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\Macmade\Desktop\iMazing-Win\hotfix\Submodules\DDNA-AppCache\tmp\iMazing-Converter\Build\Release\Products\win64\HEIC_DLL_v142.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-processthreads-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\DDNA\BetterDP\BetterDP\obj\Release\net462\BetterDP.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\1\s\SDK\AppCenterAnalytics\Microsoft.AppCenter.Analytics.WindowsDesktop\obj\Microsoft.AppCenter.Analytics.WindowsDesktop\Release\net462\Microsoft.AppCenter.Analytics.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-console-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: d:\source\github\HTML-Renderer\Source\HtmlRenderer.PdfSharp\obj\Release\HtmlRenderer.PdfSharp.pdbtj source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-file-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-private-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-convert-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-profile-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\NetSparkle\NetSparkle\src\NetSparkle.UI.WPF\obj\Release\net452\NetSparkle.UI.WPF.pdbSHA256 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-time-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\1\s\SDK\AppCenterCrashes\Microsoft.AppCenter.Crashes.WindowsDesktop\obj\Microsoft.AppCenter.Crashes.WindowsDesktop\Release\net462\Microsoft.AppCenter.Crashes.pdbSHA256 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\1\s\SDK\AppCenterCrashes\Microsoft.AppCenter.Crashes.WindowsDesktop\obj\Microsoft.AppCenter.Crashes.WindowsDesktop\Release\net462\Microsoft.AppCenter.Crashes.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\codebar\Desktop\Dev\Git\iMazing3-Win\Submodules\DevKit-Win\DevKit\obj\Release\net462\DevKit.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\1\s\SDK\AppCenterAnalytics\Microsoft.AppCenter.Analytics.WindowsDesktop\obj\Microsoft.AppCenter.Analytics.WindowsDesktop\Release\net462\Microsoft.AppCenter.Analytics.pdbSHA256.j source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: E:\A\_work\582\s\bin\obj\ref\Microsoft.Win32.Primitives\4.0.3.0\Microsoft.Win32.Primitives.pdb|( source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-handle-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\DDNA\ColorSet\ColorSetKit\obj\Release\net462\ColorSetKit.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: d:\agent\_work\2\s\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: /_/Src/Newtonsoft.Json/obj/Release/net45/Newtonsoft.Json.pdbSHA256 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: /_/Src/Newtonsoft.Json/obj/Release/net45/Newtonsoft.Json.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\Macmade\Desktop\iMazing-Win\hotfix\Submodules\DDNA-AppCache\tmp\iMazing-Profile-Editor-Win\Submodules\Manifest-Operations\Manifest-Operations-Shared\obj\Release\net462\Manifest-Operations-Shared.pdbSHA256\ source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: powershell.exe, 00000005.00000002.7042183892.0000000007A50000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-synch-l1-2-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: E:\A\_work\582\s\bin\obj\ref\Microsoft.Win32.Primitives\4.0.3.0\Microsoft.Win32.Primitives.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\DDNA\BetterDP\BetterDP\obj\Release\net462\BetterDP.pdbSHA256 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: powershell.exe, 00000005.00000002.7042183892.0000000007A50000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-processenvironment-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\NetSparkle\NetSparkle\src\NetSparkle\obj\Release\net452\NetSparkle.pdbSHA256 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\Macmade\Desktop\iMazing-Win\hotfix\Submodules\DDNA-AppCache\tmp\iMazing-Converter\Submodules\heic-convert\Build\Release\Intermediates\win64\HEIC-NET\net462\HEIC-NET.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-datetime-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\NetSparkle\NetSparkle\src\NetSparkle.UI.WPF\obj\Release\net452\NetSparkle.UI.WPF.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: d:\agent\_work\2\s\binaries\amd64ret\bin\amd64\\concrt140.amd64.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-conio-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\Macmade\Desktop\iMazing-Win\hotfix\Submodules\DDNA-AppCache\tmp\iMazing-Converter\Submodules\heic-convert\Build\Release\Intermediates\win64\HEIC-NET\net462\HEIC-NET.pdbSHA2567 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-localization-l1-2-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-math-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\_work\1\s\third_party\edge_webview2\win\wpf_control\Microsoft.Web.WebView2.Wpf\obj\release\net45\Microsoft.Web.WebView2.Wpf.pdb% source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-processthreads-l1-1-1.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\Macmade\Desktop\iMazing-Win\hotfix\Submodules\DDNA-AppCache\tmp\iMazing-Converter\Build\Release\Products\win64\HEIC_DLL_v142.pdb11 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-namedpipe-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\_work\1\s\third_party\edge_webview2\win\webview2_api_writer\dotNetAPIWrapper\Microsoft.Web.WebView2.Core\bin\ReleasePackage\Microsoft.Web.WebView2.Core.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-multibyte-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-utility-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-rtlsupport-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-timezone-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-string-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-file-l2-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-process-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\_work\1\s\src\Microsoft.Xaml.Behaviors\obj\Release\net45\Microsoft.Xaml.Behaviors.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-libraryloader-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-core-interlocked-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\1\s\SDK\AppCenter\Microsoft.AppCenter.WindowsDesktop\obj\Microsoft.AppCenter.WindowsDesktop\Release\net462\Microsoft.AppCenter.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: D:\a\_work\1\s\third_party\edge_webview2\win\winforms_control\Microsoft.Web.WebView2.WinForms\obj\release\net45\Microsoft.Web.WebView2.WinForms.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\Macmade\Desktop\Build\DDNA-BuildCache\master\tmp\gpod\Build\64\Release\gpod.pdb11 source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: d:\agent\_work\2\s\binaries\amd64ret\bin\amd64\\msvcp140_2.amd64.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-heap-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: api-ms-win-crt-string-l1-1-0.pdb source: powershell.exe, 00000007.00000002.7371627480.0000000007D39000.00000004.00000800.00020000.00000000.sdmp |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then jmp 079D8F7Ah |
5_2_079D8C58 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then jmp 079D8F7Ah |
5_2_079D8F3D |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then jmp 079D60C2h |
5_2_079D5D30 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then jmp 079D60C2h |
5_2_079D5D20 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then jmp 079D8F7Ah |
5_2_079D8C49 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then jmp 079D6C49h |
5_2_079D6A88 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then jmp 079D6C49h |
5_2_079D6A79 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], 5E874B5Fh |
7_2_004259F0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp byte ptr [eax+ebx+09h], 00000000h |
7_2_00436980 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov ecx, eax |
7_2_00415A0E |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov dword ptr [ebp-10h], ebx |
7_2_0040A283 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov word ptr [edx], cx |
7_2_004183F0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx eax, byte ptr [esp+edi+18h] |
7_2_00439BF0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp byte ptr [ebx+edx], 00000000h |
7_2_0041D400 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov edx, ecx |
7_2_00437420 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [ebp+ebx*8+00h], 5E874B5Fh |
7_2_00437420 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [edx+ebx*8], BC9C9AFCh |
7_2_00437420 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then test eax, eax |
7_2_00437420 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov esi, edi |
7_2_0041655D |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then jmp dword ptr [00443684h] |
7_2_0041655D |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [ebx+edi*8], E785F9BAh |
7_2_0041655D |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov edx, ecx |
7_2_0043D580 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], 71B3F069h |
7_2_0043D580 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx edx, byte ptr [esi+eax-000000CFh] |
7_2_0040AE20 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx ecx, byte ptr [ebx] |
7_2_0040AE20 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov ecx, eax |
7_2_0040CE98 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov eax, dword ptr [00442B14h] |
7_2_0040CE98 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [edi+ebp*8], 2DA07A80h |
7_2_0043D7B0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], A2347758h |
7_2_0043A030 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov ecx, dword ptr [ebp-2Ch] |
7_2_00427E16 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [edi+ebp*8], C7235EAFh |
7_2_0043D8E0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx edx, byte ptr [esp+ecx+04255C89h] |
7_2_00409080 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov eax, dword ptr [ebp+08h] |
7_2_00422966 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov ecx, dword ptr [esi+08h] |
7_2_0040C93E |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov byte ptr [edi], cl |
7_2_0040C93E |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then add eax, ecx |
7_2_0042D1C4 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov ebx, eax |
7_2_004059D0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov ebp, eax |
7_2_004059D0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov byte ptr [esi], dl |
7_2_0042C199 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp byte ptr [esi+ebx], 00000000h |
7_2_0042A270 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [edi+esi*8], E785F9BAh |
7_2_00427223 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov eax, dword ptr [ebp+08h] |
7_2_00422966 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movsx eax, byte ptr [edi] |
7_2_0043C2EE |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [edi+esi*8], E785F9BAh |
7_2_004192F0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov eax, ecx |
7_2_00425287 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx esi, byte ptr [ebp+eax-56522565h] |
7_2_004222B1 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov ecx, eax |
7_2_0041AB1A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx edi, byte ptr [esp+ecx-5F965E5Fh] |
7_2_00417BFA |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx edi, byte ptr [esp+ecx-6FEB5746h] |
7_2_00417BFA |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx edx, word ptr [ebp+00h] |
7_2_00437BA9 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx edx, byte ptr [esp+ecx+4Ch] |
7_2_0041FC50 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp word ptr [esi+edi+02h], 0000h |
7_2_0041FC50 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [edi+esi*8], E785F9BAh |
7_2_004214C0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx edi, byte ptr [ebp+00h] |
7_2_004094D0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov ebx, dword ptr [edi+04h] |
7_2_00429CD0 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx esi, byte ptr [ebp+eax-56522565h] |
7_2_00421CAB |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then jmp dword ptr [00443ECCh] |
7_2_00421CAB |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then add eax, dword ptr [esp+ecx*4+24h] |
7_2_00407550 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx ecx, word ptr [edi+esi*4] |
7_2_00407550 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx edx, byte ptr [esp+eax-1B9D9E48h] |
7_2_0041ADE9 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov word ptr [ecx], dx |
7_2_0040DDFA |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [edi+esi*8], E785F9BAh |
7_2_00426D93 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov byte ptr [edi], cl |
7_2_00425E40 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then movzx esi, byte ptr [esp+ecx-09D3FE44h] |
7_2_00425E40 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov ebp, edi |
7_2_00425E40 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov esi, ecx |
7_2_00424E40 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then jmp eax |
7_2_00416E70 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov ecx, dword ptr [ebp-2Ch] |
7_2_00427E16 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov byte ptr [esi], cl |
7_2_0042B6E1 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then mov byte ptr [esi], cl |
7_2_0042B738 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4x nop then cmp dword ptr [edi+esi*8], E785F9BAh |
7_2_004277A1 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.50.112.19 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 13.107.21.237 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 142.250.64.195 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 199.232.214.172 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 142.250.64.195 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 199.232.214.172 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.135.18 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.190.135.18 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.50.112.19 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.50.112.19 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 239.255.255.250 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 239.255.255.250 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 239.255.255.250 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 239.255.255.250 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic |
HTTP traffic detected: GET /madonna.mp4 HTTP/1.1Accept: */*Accept-Language: en-US,en-GB;q=0.7,en;q=0.3Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: pawpaws.readit-carfanatics.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /madonna.vstx HTTP/1.1Host: pawpaws1.readit-carfanatics.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CI+2yQEIorbJAQipncoBCMD2ygEIkqHLAQic/swBCIWgzQEIrJ7OAQjkr84BCMO2zgEIvbnOAQjtvM4BCLu9zgEI1r3OAQjMv84BGMHLzAEYva7OARidsc4BSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: NID=517=i4E8sm-BN75bnGkPw4VW8uy51aQ8ounjntfNX2fu8MFJNuIvCX0dRBy-XkHqHwKOVFSSaC2nqfULsnHhY3TzIXHWC90jS3Wi2BINtQIDr1LJvZE4Ud-byTNL9Q04Nd1-ydmJvrWYY5vORspW6soJ1bMj20dq8UvPjgkw2sOvmuTUanqu |
Source: global traffic |
HTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CI+2yQEIorbJAQipncoBCMD2ygEIkqHLAQic/swBCIWgzQEIrJ7OAQjkr84BCMO2zgEIvbnOAQjtvM4BCLu9zgEI1r3OAQjMv84BGMHLzAEYva7OARidsc4BSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: NID=517=i4E8sm-BN75bnGkPw4VW8uy51aQ8ounjntfNX2fu8MFJNuIvCX0dRBy-XkHqHwKOVFSSaC2nqfULsnHhY3TzIXHWC90jS3Wi2BINtQIDr1LJvZE4Ud-byTNL9Q04Nd1-ydmJvrWYY5vORspW6soJ1bMj20dq8UvPjgkw2sOvmuTUanqu |
Source: global traffic |
HTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: NID=517=i4E8sm-BN75bnGkPw4VW8uy51aQ8ounjntfNX2fu8MFJNuIvCX0dRBy-XkHqHwKOVFSSaC2nqfULsnHhY3TzIXHWC90jS3Wi2BINtQIDr1LJvZE4Ud-byTNL9Q04Nd1-ydmJvrWYY5vORspW6soJ1bMj20dq8UvPjgkw2sOvmuTUanqu |
Source: global traffic |
HTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjNGOGPnLsGIjBXAECMSl2N1QzCcWURBtk32rZpPQpm0GXwBmcX4ZHRX4IaBfM1HNUfjJBZHODNYDgyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CI+2yQEIorbJAQipncoBCMD2ygEIkqHLAQic/swBCIWgzQEIrJ7OAQjkr84BCMO2zgEIvbnOAQjtvM4BCLu9zgEI1r3OAQjMv84BGMHLzAEYva7OARidsc4BSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: NID=517=i4E8sm-BN75bnGkPw4VW8uy51aQ8ounjntfNX2fu8MFJNuIvCX0dRBy-XkHqHwKOVFSSaC2nqfULsnHhY3TzIXHWC90jS3Wi2BINtQIDr1LJvZE4Ud-byTNL9Q04Nd1-ydmJvrWYY5vORspW6soJ1bMj20dq8UvPjgkw2sOvmuTUanqu |
Source: global traffic |
HTTP traffic detected: GET /sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjNGOGPnLsGIjBydXJM8slEgX7MatWidvqkCsFro3rskIET9l164K-5Z9PO9PX7EwBFXAh8V-RYgXUyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: NID=517=i4E8sm-BN75bnGkPw4VW8uy51aQ8ounjntfNX2fu8MFJNuIvCX0dRBy-XkHqHwKOVFSSaC2nqfULsnHhY3TzIXHWC90jS3Wi2BINtQIDr1LJvZE4Ud-byTNL9Q04Nd1-ydmJvrWYY5vORspW6soJ1bMj20dq8UvPjgkw2sOvmuTUanqu |
Source: global traffic |
HTTP traffic detected: GET /NAURGGBG953NT9QEQBG3.bin HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Host: klippetamea8.shop |