Source: | Binary string: \??\C:\Windows\mscorlib.pdb2e source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B71B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.VisualBasic.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Xml.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: \??\C:\Windows\dll\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B71B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.ni.pdbRSDS source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: \??\C:\Users\user\Desktop\rivalsanticheat.PDB source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B6E3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Core.pdbY source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Configuration.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: mscorlib.pdbcorlib.pdbpdblib.pdbC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3454196854.000000001BEA9000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.ni.pdbRSDS7^3l source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Configuration.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: symbols\dll\mscorlib.pdbpdb` source: rivalsanticheat.exe, 00000000.00000002.3454196854.000000001BEA9000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: System.Xml.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: Microsoft.VisualBasic.pdbmscorlib.dllPQS source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: 0C:\Windows\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3454196854.000000001BEA9000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: System.Xml.ni.pdbRSDS# source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Core.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: Microsoft.VisualBasic.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3454196854.000000001BEA9000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdbSYSTEM*l source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B71B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdbR source: rivalsanticheat.exe, 00000000.00000002.3451215148.0000000000895000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B6E3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3451215148.0000000000895000.00000004.00000020.00020000.00000000.sdmp, rivalsanticheat.exe, 00000000.00000002.3451215148.0000000000915000.00000004.00000020.00020000.00000000.sdmp, WER2E71.tmp.dmp.12.dr |
Source: | Binary string: C:\Windows\mscorlib.pdbpdblib.pdbTo source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B71B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3451215148.0000000000895000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.ni.pdbRSDSJ< source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Management.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: mscorlib.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Management.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: \??\C:\Windows\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B71B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Core.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Configuration.ni.pdbRSDScUN source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: indoC:\Windows\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3454196854.000000001BEA9000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: System.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Core.ni.pdbRSDS source: WER2E71.tmp.dmp.12.dr |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: avicap32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: msvfw32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: | Binary string: \??\C:\Windows\mscorlib.pdb2e source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B71B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.VisualBasic.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Xml.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: \??\C:\Windows\dll\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B71B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.ni.pdbRSDS source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: \??\C:\Users\user\Desktop\rivalsanticheat.PDB source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B6E3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Core.pdbY source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Configuration.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: mscorlib.pdbcorlib.pdbpdblib.pdbC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3454196854.000000001BEA9000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.ni.pdbRSDS7^3l source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Configuration.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: symbols\dll\mscorlib.pdbpdb` source: rivalsanticheat.exe, 00000000.00000002.3454196854.000000001BEA9000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: System.Xml.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: Microsoft.VisualBasic.pdbmscorlib.dllPQS source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: 0C:\Windows\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3454196854.000000001BEA9000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: System.Xml.ni.pdbRSDS# source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Core.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: Microsoft.VisualBasic.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3454196854.000000001BEA9000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdbSYSTEM*l source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B71B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdbR source: rivalsanticheat.exe, 00000000.00000002.3451215148.0000000000895000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B6E3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3451215148.0000000000895000.00000004.00000020.00020000.00000000.sdmp, rivalsanticheat.exe, 00000000.00000002.3451215148.0000000000915000.00000004.00000020.00020000.00000000.sdmp, WER2E71.tmp.dmp.12.dr |
Source: | Binary string: C:\Windows\mscorlib.pdbpdblib.pdbTo source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B71B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3451215148.0000000000895000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.ni.pdbRSDSJ< source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Management.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: mscorlib.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Management.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: \??\C:\Windows\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B71B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Core.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Configuration.ni.pdbRSDScUN source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: indoC:\Windows\mscorlib.pdb source: rivalsanticheat.exe, 00000000.00000002.3454196854.000000001BEA9000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: System.ni.pdb source: WER2E71.tmp.dmp.12.dr |
Source: | Binary string: System.Core.ni.pdbRSDS source: WER2E71.tmp.dmp.12.dr |
Source: rivalsanticheat.exe, VcacVJ1em6v07R5IV484AfJ4JiVN5.cs | High entropy of concatenated method names: '_6lRl6jDM150xy79DBIVDdX5sSvapE', 'wjChbTmZT2OYFjiT0uP74LlAV8Wyt', 'LgpgbmqiObPCAYZd7rg8Y1JovEMkP', 'NzdTuA1JlrLDp1s2ub2Q2o', 's2gBFv5eIeYNlNOLqufHlv', 'Qp1fWcTf1nDc7PqNMW9Mdy', 'xqGtCom2LqzujpQNHjnweQ', 'mz3j6ieQi3IdZ8ejmd72Vq', 'yrcxCgFOeoDwrIoEJbvCkN', 'qI2eQSUAWY5FzY1lcccS0c' |
Source: rivalsanticheat.exe, eISxuTAmwmXp2bOP9dtQhIMzrr363r3ygdkq9O7WCk3W.cs | High entropy of concatenated method names: 'GL4DGDTNkoxvi5RxKVLUoCmoyn4DQqF8sXbckiSwztppLQ6pAlzx7svp0wuBwC', 'jO6777MkbcyZ1m4OA7u7Cxm4jhMjva9lnUIDQ5pwn81TdrmxRjzfdIBRnAKLt3', 'qeusPqODQcqt2ipmHr7DoLPNTApdt3B6ftoJaxzmvaC5V1GMST35b9D7N57Sfn', 'e9asjdqng6Y9hC9EtQdxaqUI1aTAQrP3ApsZQZxAIPTGpVH2ZJmbGBS9PwzR9q' |
Source: rivalsanticheat.exe, oBuT1QH6a41s.cs | High entropy of concatenated method names: 'Equals', 'GetHashCode', 'GetType', 'ToString', 'Create__Instance__', 'Dispose__Instance__', 'uimPyDiJOuUAZ1SArMigmVbySeeknRQEnYjWo9tCAn2GEBt1gAVH4xFZMFPuEx', 'RvZctpUuUAPyNhWi5kwjSLmaMGAzSxnzGzRzhXhkhDztAFZpl6bOOwCALcOrtQ', 'GB6gSDM5xYU2WdmaggvmQVPTl8wuwM4txCmWcPsHNHVlcOuU62pCIWjavHpssv', 'j5QXPslyK2JwvEelGClIFaPxi4Zi7ljtRC6oXdS4jNbBwLOFobC92eXgWVmd4f' |
Source: rivalsanticheat.exe, bb2clQFJgGrOun9pdWjRRbebdaMMZUq1KbWDu03Q2zot.cs | High entropy of concatenated method names: 'u8QEiX8j3XM2UAqZf4bdIa4ThVBpskbv5Ftf8NsSss5p', 'XZmQR6HgpF6SWthMDC3Nk7rZEE0tT9SvAKJSWgRiTZgF0rNkQhlbOIiwJxNqlNhZfQDWkxg6gfCVPL7', 'p90PF3mlwQudzXVPM5jG5ISklliTjCj3Sxkw5paojpOoebo9hn3VrNTMcGEK0PQ2nZKJ3qKrRZnOL3l', 'ElqXPQmrYFWeZMJeGjrq7VdmP5GERyRPcciyoQzmw0AT43SkQzyJVKUJ6V4XRG7jAOdbAUw9slZusaC', '_2weGW0pjT00Z2KmZOWEovcL2K2pFsLrLZrZybJp39pXPjsWXgT4ljvAy4SzXLfnWPrECj254ccsfFKy' |
Source: rivalsanticheat.exe, fh8tnrz5txb35hggkbSAYsj4mZ8AYvylTgfr4fE2Q15U.cs | High entropy of concatenated method names: 'B7Hvr6jG42UqFCoChQJF91NoI3vd3OlqvOejbGMSNL7L', 'Kt2g5iSc42iez0MlWTFdFi2SswgrDx9an0bJx1eutmSR', 'kkjmMQxnTmcO78QGDUFkyIhQrF1a0xIMIp3HgAXp2bFv', '_56Sjig3wZ0eFsrr09k7JXTeCofXGd5dU4V8Y68PXYDmG', 'CzP31gwxC6lGNYMzSWPTVHLT7cnZ8Uugz8l0d79v65jZ', 'dOMGT66IEgtPiUFls7673EN0WbA5qFAf6WDjukXEc3B6', 'mOZA5aS6ZEyL64DVxSX8p0Jb1Qera7OHpIg00dnQT5q0', 'jcyyZQTSlnmVNIXoQ0KYemOPoNjlgeGvtpQxdCjdhaGx', 'miFnSnOy5VJYxmgeKm6hbCLGI9wjRY7BmMy5hXr8uUgS', 'uYqiouQ9PNPTEs3Mq1hr0M0bUl3ZQSsEU0zpaq82LGBq' |
Source: rivalsanticheat.exe, riNVOSuG9gHMEsIGB2S909igwoELbkqfqzvNazIu1Ygx.cs | High entropy of concatenated method names: 'fyyAVidFwh52zRiz7luPppLiFNEFICpdGbTlMSbmBtev', 'leqYSiowcvsQOXJBlmxx5myrsiEy0iPVEQzJlVWPKZ8N', 'XgmBxG2wrRTs0yZwca2B1JgPzBfaJ', 'Aasb1IZ2VuBKV5iD04rPNZvBaNZbk', '_0X2UL5MWT5UfWUyDjvGLRJf77khux2Z3yg1Rhpr9ejbasfV5ZlifyeHTyzWX6gKvKIW9LrKkU4zSnbh', '_0rlx1kyDWTGxogKxsq0V8QP92BWdm1vn0n1ejG5QS4Pq6QR4tamTN9Q8FVMeHXntGIVN3fOACN0SYem', 'JMh9zvOzsXYVLQa9wbGrLtXZtsmQX1CO7TTA1fYjovyvvhsoUjqP2iMjANT4mgwcxMF9VMa6a5EPWV2', 'sUgR92Dmwq1SxWNlfWh3DYPVvQJHg9wSzxeUSNfOymx26MAlAJjGLNqK0Re56xMS2XLP4xWpDFFAA97', 'N8Wiqbfua3ZsTTiAyI4rrc9igG18oVTDRipFcqYUhT8upNWX71nfNrPloKQ1xr8peDqZrOjYbWfs0Lm', 'jtP2LczDIhNsqMWjhcsJPBGRq8kZhgGcR5Ojfsy8blJhRpaD7vhVnB5WzyiZHsuRfUOSxAMku2qPND1' |
Source: rivalsanticheat.exe, CwFHZkjzy8fuL42ssK4j02FfYn8bn.cs | High entropy of concatenated method names: 'Oi7weUyWuCQQhBF5YiejJk0fX94oE', '_0x01OaaO20ENdzFmowUzV4HZtIFX7', 'FTCZrxoK93PDHVS0JxfUFMpUBpow0', 'pAG9Vj4L9RHqaLZMlHQj7Omuc0sqw', '_7VfcQh08yWeUNULNsVdw49Yj9dpR7', 'P70ee5bjl0UQVHJORbqUNMlem1hvg', 'lzcuTeLxip3gzB5m1p2JLkvh7JovQ', 'CLyOVjEqvdKAJ59sbvJpQBIa97v3g', '_1j9wF4Iacf7t98THFs8tBa2C9bcQA', '_8ZnnGctPnYhdzKL7GD87l0iDK7pxS' |
Source: rivalsanticheat.exe, Zj3A2ceVsypvLkuHb7vS0hOvuoE3YlQ6oYsQLki9xMow.cs | High entropy of concatenated method names: 'd8KpWZL4NE0DLYIuzVsnnSnqz668asGvOA8Jqsmitl7y', '_0sGHB0igTMVFlt1yxCvQbOdcoQ9hnEW1OzoHCBsGyS3j', 'tMcwII6xDd8m7jW41cN0uUKS6q2mDXWLMgc4U1vdPOus', 'nnc75mvNG89CwLwo3K7woBQucA9mCoHjmsgRR70CRgFl', 'v8s3kXET2YDB5K8SIJUZHYoRxGS3RwvPvzKMERZKio2U', 'ltRN3OaxH7coWH1AmQwyFdMo9ufu8aegmB6GfD7cblVS', 'Paxqe58OkbYRzd6nZ4YA4jgCi2ccftDbmsbUKcEW4FAE', 'WHaDPPU0hlA69IsVOINOF8G3d9cBQJH3DZlpeNqNP9za', 'FaBoXqLR9DN1itTlvJzGZKuKdFh8bIx5qAcUp65YMyLW', 'BG5rJdzYCSPYbTpD5Np9Bw6d8pons6252riffNrdKyZO' |
Source: rivalsanticheat.exe, cCtJmGsFBRSmjuWVUJhTNMkmsgWgXScdGcmbjBqGaR1T.cs | High entropy of concatenated method names: '_8DLlAzHZ6Wl03EQ1ZFHZUXljgNaqnqjr7UK9jpBUGJQw', 'njFZ8sV0ef1VWhmX17Er8effWarqpqrqwyCNb3KX0GTK', 't5kaLaGzS2Njz8dXlUhOc3LMjjoSl0TWqTfXdlDSLRPS', 'inNIYkvDMzacGsiGvvMajJLPkrvRiBihdgfuLkXeAZPU', 'hPZwgp9ogeeAvgVEOpSP3CZsxrQzZXXJaBoMHtcrc74x', 'LT3cVDpeo5ddai5sRrvg5oWnhUHWX2bdODcEbZk1gBKu', 'xNaMvUjlJzngx4HGQSl3TMb1dsqTzVYmArrwlPWrGMPI', 'WIFOnRd3ecyhS4J7TkGWcsF2reZCNDXfruUhbLjvjhUd', 'hW9RukMlo0dH0jaGvjaq146BXX9HoNDrSk1oZRRAn4hZ', 'StBL68hDZMiDvA7V8zda9VIgZX2sDqmQXuhUzKNIUO14' |
Source: rivalsanticheat.exe, wPpUVasNl83McTjXeCT7REF5YtT48.cs | High entropy of concatenated method names: 'fyuyopi7PzopjcJZGhukcoMTamUUf', 'Dz41oeX7buYQj3Exd1tfUay2T72EkI3WHimPmorWgeqkwcUd90j8kMlgQBmnJu3xOhBNrPBTmRAqwgE', 'JxYAHRWf6sDdj2HkhY5bvWINtEtrKNxPkcnzo6lwv5phbtn2ABEg3K6S5QMavH6Wfv6CSsPONVlDOy7', 'xw5r0zOIqPk41s1uqoxamC0Hcx2uTsOCRAwo3EZS437q5Kcgj4bEtSCtzmTU2tJ1xF8a5DVZqh50cw4', 'orIPmORCjjJ151KTXNdDBK3g2CUM5dGyxxLQoU8UQilCnNawXBLx2ZUpf7aDHfahPKBHcGn2YGWvIHb' |
Source: rivalsanticheat.exe.0.dr, VcacVJ1em6v07R5IV484AfJ4JiVN5.cs | High entropy of concatenated method names: '_6lRl6jDM150xy79DBIVDdX5sSvapE', 'wjChbTmZT2OYFjiT0uP74LlAV8Wyt', 'LgpgbmqiObPCAYZd7rg8Y1JovEMkP', 'NzdTuA1JlrLDp1s2ub2Q2o', 's2gBFv5eIeYNlNOLqufHlv', 'Qp1fWcTf1nDc7PqNMW9Mdy', 'xqGtCom2LqzujpQNHjnweQ', 'mz3j6ieQi3IdZ8ejmd72Vq', 'yrcxCgFOeoDwrIoEJbvCkN', 'qI2eQSUAWY5FzY1lcccS0c' |
Source: rivalsanticheat.exe.0.dr, eISxuTAmwmXp2bOP9dtQhIMzrr363r3ygdkq9O7WCk3W.cs | High entropy of concatenated method names: 'GL4DGDTNkoxvi5RxKVLUoCmoyn4DQqF8sXbckiSwztppLQ6pAlzx7svp0wuBwC', 'jO6777MkbcyZ1m4OA7u7Cxm4jhMjva9lnUIDQ5pwn81TdrmxRjzfdIBRnAKLt3', 'qeusPqODQcqt2ipmHr7DoLPNTApdt3B6ftoJaxzmvaC5V1GMST35b9D7N57Sfn', 'e9asjdqng6Y9hC9EtQdxaqUI1aTAQrP3ApsZQZxAIPTGpVH2ZJmbGBS9PwzR9q' |
Source: rivalsanticheat.exe.0.dr, oBuT1QH6a41s.cs | High entropy of concatenated method names: 'Equals', 'GetHashCode', 'GetType', 'ToString', 'Create__Instance__', 'Dispose__Instance__', 'uimPyDiJOuUAZ1SArMigmVbySeeknRQEnYjWo9tCAn2GEBt1gAVH4xFZMFPuEx', 'RvZctpUuUAPyNhWi5kwjSLmaMGAzSxnzGzRzhXhkhDztAFZpl6bOOwCALcOrtQ', 'GB6gSDM5xYU2WdmaggvmQVPTl8wuwM4txCmWcPsHNHVlcOuU62pCIWjavHpssv', 'j5QXPslyK2JwvEelGClIFaPxi4Zi7ljtRC6oXdS4jNbBwLOFobC92eXgWVmd4f' |
Source: rivalsanticheat.exe.0.dr, bb2clQFJgGrOun9pdWjRRbebdaMMZUq1KbWDu03Q2zot.cs | High entropy of concatenated method names: 'u8QEiX8j3XM2UAqZf4bdIa4ThVBpskbv5Ftf8NsSss5p', 'XZmQR6HgpF6SWthMDC3Nk7rZEE0tT9SvAKJSWgRiTZgF0rNkQhlbOIiwJxNqlNhZfQDWkxg6gfCVPL7', 'p90PF3mlwQudzXVPM5jG5ISklliTjCj3Sxkw5paojpOoebo9hn3VrNTMcGEK0PQ2nZKJ3qKrRZnOL3l', 'ElqXPQmrYFWeZMJeGjrq7VdmP5GERyRPcciyoQzmw0AT43SkQzyJVKUJ6V4XRG7jAOdbAUw9slZusaC', '_2weGW0pjT00Z2KmZOWEovcL2K2pFsLrLZrZybJp39pXPjsWXgT4ljvAy4SzXLfnWPrECj254ccsfFKy' |
Source: rivalsanticheat.exe.0.dr, fh8tnrz5txb35hggkbSAYsj4mZ8AYvylTgfr4fE2Q15U.cs | High entropy of concatenated method names: 'B7Hvr6jG42UqFCoChQJF91NoI3vd3OlqvOejbGMSNL7L', 'Kt2g5iSc42iez0MlWTFdFi2SswgrDx9an0bJx1eutmSR', 'kkjmMQxnTmcO78QGDUFkyIhQrF1a0xIMIp3HgAXp2bFv', '_56Sjig3wZ0eFsrr09k7JXTeCofXGd5dU4V8Y68PXYDmG', 'CzP31gwxC6lGNYMzSWPTVHLT7cnZ8Uugz8l0d79v65jZ', 'dOMGT66IEgtPiUFls7673EN0WbA5qFAf6WDjukXEc3B6', 'mOZA5aS6ZEyL64DVxSX8p0Jb1Qera7OHpIg00dnQT5q0', 'jcyyZQTSlnmVNIXoQ0KYemOPoNjlgeGvtpQxdCjdhaGx', 'miFnSnOy5VJYxmgeKm6hbCLGI9wjRY7BmMy5hXr8uUgS', 'uYqiouQ9PNPTEs3Mq1hr0M0bUl3ZQSsEU0zpaq82LGBq' |
Source: rivalsanticheat.exe.0.dr, riNVOSuG9gHMEsIGB2S909igwoELbkqfqzvNazIu1Ygx.cs | High entropy of concatenated method names: 'fyyAVidFwh52zRiz7luPppLiFNEFICpdGbTlMSbmBtev', 'leqYSiowcvsQOXJBlmxx5myrsiEy0iPVEQzJlVWPKZ8N', 'XgmBxG2wrRTs0yZwca2B1JgPzBfaJ', 'Aasb1IZ2VuBKV5iD04rPNZvBaNZbk', '_0X2UL5MWT5UfWUyDjvGLRJf77khux2Z3yg1Rhpr9ejbasfV5ZlifyeHTyzWX6gKvKIW9LrKkU4zSnbh', '_0rlx1kyDWTGxogKxsq0V8QP92BWdm1vn0n1ejG5QS4Pq6QR4tamTN9Q8FVMeHXntGIVN3fOACN0SYem', 'JMh9zvOzsXYVLQa9wbGrLtXZtsmQX1CO7TTA1fYjovyvvhsoUjqP2iMjANT4mgwcxMF9VMa6a5EPWV2', 'sUgR92Dmwq1SxWNlfWh3DYPVvQJHg9wSzxeUSNfOymx26MAlAJjGLNqK0Re56xMS2XLP4xWpDFFAA97', 'N8Wiqbfua3ZsTTiAyI4rrc9igG18oVTDRipFcqYUhT8upNWX71nfNrPloKQ1xr8peDqZrOjYbWfs0Lm', 'jtP2LczDIhNsqMWjhcsJPBGRq8kZhgGcR5Ojfsy8blJhRpaD7vhVnB5WzyiZHsuRfUOSxAMku2qPND1' |
Source: rivalsanticheat.exe.0.dr, CwFHZkjzy8fuL42ssK4j02FfYn8bn.cs | High entropy of concatenated method names: 'Oi7weUyWuCQQhBF5YiejJk0fX94oE', '_0x01OaaO20ENdzFmowUzV4HZtIFX7', 'FTCZrxoK93PDHVS0JxfUFMpUBpow0', 'pAG9Vj4L9RHqaLZMlHQj7Omuc0sqw', '_7VfcQh08yWeUNULNsVdw49Yj9dpR7', 'P70ee5bjl0UQVHJORbqUNMlem1hvg', 'lzcuTeLxip3gzB5m1p2JLkvh7JovQ', 'CLyOVjEqvdKAJ59sbvJpQBIa97v3g', '_1j9wF4Iacf7t98THFs8tBa2C9bcQA', '_8ZnnGctPnYhdzKL7GD87l0iDK7pxS' |
Source: rivalsanticheat.exe.0.dr, Zj3A2ceVsypvLkuHb7vS0hOvuoE3YlQ6oYsQLki9xMow.cs | High entropy of concatenated method names: 'd8KpWZL4NE0DLYIuzVsnnSnqz668asGvOA8Jqsmitl7y', '_0sGHB0igTMVFlt1yxCvQbOdcoQ9hnEW1OzoHCBsGyS3j', 'tMcwII6xDd8m7jW41cN0uUKS6q2mDXWLMgc4U1vdPOus', 'nnc75mvNG89CwLwo3K7woBQucA9mCoHjmsgRR70CRgFl', 'v8s3kXET2YDB5K8SIJUZHYoRxGS3RwvPvzKMERZKio2U', 'ltRN3OaxH7coWH1AmQwyFdMo9ufu8aegmB6GfD7cblVS', 'Paxqe58OkbYRzd6nZ4YA4jgCi2ccftDbmsbUKcEW4FAE', 'WHaDPPU0hlA69IsVOINOF8G3d9cBQJH3DZlpeNqNP9za', 'FaBoXqLR9DN1itTlvJzGZKuKdFh8bIx5qAcUp65YMyLW', 'BG5rJdzYCSPYbTpD5Np9Bw6d8pons6252riffNrdKyZO' |
Source: rivalsanticheat.exe.0.dr, cCtJmGsFBRSmjuWVUJhTNMkmsgWgXScdGcmbjBqGaR1T.cs | High entropy of concatenated method names: '_8DLlAzHZ6Wl03EQ1ZFHZUXljgNaqnqjr7UK9jpBUGJQw', 'njFZ8sV0ef1VWhmX17Er8effWarqpqrqwyCNb3KX0GTK', 't5kaLaGzS2Njz8dXlUhOc3LMjjoSl0TWqTfXdlDSLRPS', 'inNIYkvDMzacGsiGvvMajJLPkrvRiBihdgfuLkXeAZPU', 'hPZwgp9ogeeAvgVEOpSP3CZsxrQzZXXJaBoMHtcrc74x', 'LT3cVDpeo5ddai5sRrvg5oWnhUHWX2bdODcEbZk1gBKu', 'xNaMvUjlJzngx4HGQSl3TMb1dsqTzVYmArrwlPWrGMPI', 'WIFOnRd3ecyhS4J7TkGWcsF2reZCNDXfruUhbLjvjhUd', 'hW9RukMlo0dH0jaGvjaq146BXX9HoNDrSk1oZRRAn4hZ', 'StBL68hDZMiDvA7V8zda9VIgZX2sDqmQXuhUzKNIUO14' |
Source: rivalsanticheat.exe.0.dr, wPpUVasNl83McTjXeCT7REF5YtT48.cs | High entropy of concatenated method names: 'fyuyopi7PzopjcJZGhukcoMTamUUf', 'Dz41oeX7buYQj3Exd1tfUay2T72EkI3WHimPmorWgeqkwcUd90j8kMlgQBmnJu3xOhBNrPBTmRAqwgE', 'JxYAHRWf6sDdj2HkhY5bvWINtEtrKNxPkcnzo6lwv5phbtn2ABEg3K6S5QMavH6Wfv6CSsPONVlDOy7', 'xw5r0zOIqPk41s1uqoxamC0Hcx2uTsOCRAwo3EZS437q5Kcgj4bEtSCtzmTU2tJ1xF8a5DVZqh50cw4', 'orIPmORCjjJ151KTXNdDBK3g2CUM5dGyxxLQoU8UQilCnNawXBLx2ZUpf7aDHfahPKBHcGn2YGWvIHb' |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\rivalsanticheat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: Amcache.hve.12.dr | Binary or memory string: VMware |
Source: Amcache.hve.12.dr | Binary or memory string: VMware Virtual USB Mouse |
Source: Amcache.hve.12.dr | Binary or memory string: vmci.syshbin |
Source: Amcache.hve.12.dr | Binary or memory string: VMware, Inc. |
Source: Amcache.hve.12.dr | Binary or memory string: VMware20,1hbin@ |
Source: Amcache.hve.12.dr | Binary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563 |
Source: Amcache.hve.12.dr | Binary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Amcache.hve.12.dr | Binary or memory string: .Z$c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.12.dr | Binary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.12.dr | Binary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev |
Source: Amcache.hve.12.dr | Binary or memory string: c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.12.dr | Binary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: rivalsanticheat.exe, 00000000.00000002.3453788430.000000001B6A3000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: Amcache.hve.12.dr | Binary or memory string: vmci.sys |
Source: Amcache.hve.12.dr | Binary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0 |
Source: Amcache.hve.12.dr | Binary or memory string: vmci.syshbin` |
Source: rivalsanticheat.exe.0.dr | Binary or memory string: vmware |
Source: Amcache.hve.12.dr | Binary or memory string: \driver\vmci,\driver\pci |
Source: Amcache.hve.12.dr | Binary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.12.dr | Binary or memory string: VMware20,1 |
Source: Amcache.hve.12.dr | Binary or memory string: Microsoft Hyper-V Generation Counter |
Source: Amcache.hve.12.dr | Binary or memory string: NECVMWar VMware SATA CD00 |
Source: Amcache.hve.12.dr | Binary or memory string: VMware Virtual disk SCSI Disk Device |
Source: Amcache.hve.12.dr | Binary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom |
Source: Amcache.hve.12.dr | Binary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk |
Source: Amcache.hve.12.dr | Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver |
Source: Amcache.hve.12.dr | Binary or memory string: VMware PCI VMCI Bus Device |
Source: Amcache.hve.12.dr | Binary or memory string: VMware VMCI Bus Device |
Source: Amcache.hve.12.dr | Binary or memory string: VMware Virtual RAM |
Source: Amcache.hve.12.dr | Binary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1 |
Source: Amcache.hve.12.dr | Binary or memory string: vmci.inf_amd64_68ed49469341f563 |