Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
b34J4bxnmN.exe

Overview

General Information

Sample name:b34J4bxnmN.exe
renamed because original name is a hash value
Original sample name:24aaa69f6e96ea14e0602d49d5c58a83.exe
Analysis ID:1511742
MD5:24aaa69f6e96ea14e0602d49d5c58a83
SHA1:d50b28c15f5a93a9e4679d3c43d88a17e7350f40
SHA256:3318d2024f5863942ba46235834bea85161a90219dbcb09bfadaf14f4811476f
Tags:exenjratRAT
Infos:

Detection

Njrat
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Njrat
.NET source code contains potential unpacker
AI detected suspicious sample
Contains functionality to disable the Task Manager (.Net Source)
Contains functionality to spread to USB devices (.Net source)
Disables zone checking for all users
Machine Learning detection for sample
Modifies the windows firewall
Uses netsh to modify the Windows network and firewall settings
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a window with clipboard capturing capabilities
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May infect USB drives
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • b34J4bxnmN.exe (PID: 7352 cmdline: "C:\Users\user\Desktop\b34J4bxnmN.exe" MD5: 24AAA69F6E96EA14E0602D49D5C58A83)
    • netsh.exe (PID: 7792 cmdline: netsh firewall add allowedprogram "C:\Users\user\Desktop\b34J4bxnmN.exe" "b34J4bxnmN.exe" ENABLE MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
      • conhost.exe (PID: 7800 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
NjRATRedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored.
  • AQUATIC PANDA
  • Earth Lusca
  • Operation C-Major
  • The Gorgon Group
https://malpedia.caad.fkie.fraunhofer.de/details/win.njrat
{"Campaign ID": "clien", "Version": "0.7d", "Install Name": "f7e6d24b4a113d9753558dfbb032c2ac", "Install Dir": "Adobe Update", "Registry Value": "Software\\Microsoft\\Windows\\CurrentVersion\\Run", "Network Seprator": "|'|'|"}
SourceRuleDescriptionAuthorStrings
00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_NjratYara detected NjratJoe Security
    00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmpWindows_Trojan_Njrat_30f3c220unknownunknown
    • 0x115d2:$a1: get_Registry
    • 0x15a4f:$a2: SEE_MASK_NOZONECHECKS
    • 0x156f1:$a3: Download ERROR
    • 0x15ca1:$a4: cmd.exe /c ping 0 -n 2 & del "
    • 0x13c2e:$a5: netsh firewall delete allowedprogram "
    00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmpCN_disclosed_20180208_cDetects malware from disclosed CN malware setFlorian Roth
    • 0x15ca1:$x1: cmd.exe /c ping 0 -n 2 & del "
    • 0x137ba:$s1: winmgmts:\\.\root\SecurityCenter2
    • 0x1570f:$s3: Executed As
    • 0x124f0:$s5: Stub.exe
    • 0x156f1:$s6: Download ERROR
    • 0x1377c:$s8: Select * From AntiVirusProduct
    00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmpNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
    • 0x15a4f:$reg: SEE_MASK_NOZONECHECKS
    • 0x156d5:$msg: Execute ERROR
    • 0x15729:$msg: Execute ERROR
    • 0x15ca1:$ping: cmd.exe /c ping 0 -n 2 & del
    00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmpMALWARE_Win_NjRATDetects NjRAT / BladabindiditekSHen
    • 0x13c2e:$s1: netsh firewall delete allowedprogram
    • 0x13c80:$s2: netsh firewall add allowedprogram
    • 0x15ca1:$s3: 63 00 6D 00 64 00 2E 00 65 00 78 00 65 00 20 00 2F 00 63 00 20 00 70 00 69 00 6E 00 67
    • 0x156d5:$s4: Execute ERROR
    • 0x15729:$s4: Execute ERROR
    • 0x156f1:$s5: Download ERROR
    Click to see the 5 entries
    SourceRuleDescriptionAuthorStrings
    0.2.b34J4bxnmN.exe.5810000.1.unpackJoeSecurity_NjratYara detected NjratJoe Security
      0.2.b34J4bxnmN.exe.5810000.1.unpackWindows_Trojan_Njrat_30f3c220unknownunknown
      • 0xf7d2:$a1: get_Registry
      • 0x13c4f:$a2: SEE_MASK_NOZONECHECKS
      • 0x138f1:$a3: Download ERROR
      • 0x13ea1:$a4: cmd.exe /c ping 0 -n 2 & del "
      • 0x11e2e:$a5: netsh firewall delete allowedprogram "
      0.2.b34J4bxnmN.exe.5810000.1.unpackCN_disclosed_20180208_cDetects malware from disclosed CN malware setFlorian Roth
      • 0x13ea1:$x1: cmd.exe /c ping 0 -n 2 & del "
      • 0x119ba:$s1: winmgmts:\\.\root\SecurityCenter2
      • 0x1390f:$s3: Executed As
      • 0x106f0:$s5: Stub.exe
      • 0x138f1:$s6: Download ERROR
      • 0x1197c:$s8: Select * From AntiVirusProduct
      0.2.b34J4bxnmN.exe.5810000.1.unpackNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
      • 0x13c4f:$reg: SEE_MASK_NOZONECHECKS
      • 0x138d5:$msg: Execute ERROR
      • 0x13929:$msg: Execute ERROR
      • 0x13ea1:$ping: cmd.exe /c ping 0 -n 2 & del
      0.2.b34J4bxnmN.exe.5810000.1.unpackMALWARE_Win_NjRATDetects NjRAT / BladabindiditekSHen
      • 0x11e2e:$s1: netsh firewall delete allowedprogram
      • 0x11e80:$s2: netsh firewall add allowedprogram
      • 0x13ea1:$s3: 63 00 6D 00 64 00 2E 00 65 00 78 00 65 00 20 00 2F 00 63 00 20 00 70 00 69 00 6E 00 67
      • 0x138d5:$s4: Execute ERROR
      • 0x13929:$s4: Execute ERROR
      • 0x138f1:$s5: Download ERROR
      Click to see the 14 entries
      No Sigma rule has matched
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-09-16T10:17:49.335803+020020211761Malware Command and Control Activity Detected192.168.2.458197147.185.221.1861276TCP
      2024-09-16T10:18:15.980739+020020211761Malware Command and Control Activity Detected192.168.2.458199147.185.221.1861276TCP
      2024-09-16T10:19:03.934540+020020211761Malware Command and Control Activity Detected192.168.2.458200147.185.221.1861276TCP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-09-16T10:17:49.335803+020020331321Malware Command and Control Activity Detected192.168.2.458197147.185.221.1861276TCP
      2024-09-16T10:18:15.980739+020020331321Malware Command and Control Activity Detected192.168.2.458199147.185.221.1861276TCP
      2024-09-16T10:19:03.934540+020020331321Malware Command and Control Activity Detected192.168.2.458200147.185.221.1861276TCP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-09-16T10:17:55.378952+020028255641Malware Command and Control Activity Detected192.168.2.458197147.185.221.1861276TCP
      2024-09-16T10:18:19.839943+020028255641Malware Command and Control Activity Detected192.168.2.458199147.185.221.1861276TCP
      2024-09-16T10:19:03.996125+020028255641Malware Command and Control Activity Detected192.168.2.458200147.185.221.1861276TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: b34J4bxnmN.exeAvira: detected
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpackMalware Configuration Extractor: Njrat {"Campaign ID": "clien", "Version": "0.7d", "Install Name": "f7e6d24b4a113d9753558dfbb032c2ac", "Install Dir": "Adobe Update", "Registry Value": "Software\\Microsoft\\Windows\\CurrentVersion\\Run", "Network Seprator": "|'|'|"}
      Source: b34J4bxnmN.exeReversingLabs: Detection: 52%
      Source: b34J4bxnmN.exeVirustotal: Detection: 53%Perma Link
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000000.00000002.4137918645.00000000031B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: b34J4bxnmN.exe PID: 7352, type: MEMORYSTR
      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
      Source: b34J4bxnmN.exeJoe Sandbox ML: detected
      Source: b34J4bxnmN.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
      Source: b34J4bxnmN.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

      Spreading

      barindex
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, Usb1.cs.Net Code: infect
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, Usb1.cs.Net Code: infect
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: \autorun.inf
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: [autorun]
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: autorun.inf
      Source: b34J4bxnmN.exe, 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: \autorun.inf
      Source: b34J4bxnmN.exe, 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: [autorun]
      Source: b34J4bxnmN.exe, 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: autorun.inf

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:58197 -> 147.185.221.18:61276
      Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:58197 -> 147.185.221.18:61276
      Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:58197 -> 147.185.221.18:61276
      Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:58199 -> 147.185.221.18:61276
      Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:58199 -> 147.185.221.18:61276
      Source: Network trafficSuricata IDS: 2033132 - Severity 1 - ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) : 192.168.2.4:58200 -> 147.185.221.18:61276
      Source: Network trafficSuricata IDS: 2021176 - Severity 1 - ET MALWARE Bladabindi/njRAT CnC Command (ll) : 192.168.2.4:58200 -> 147.185.221.18:61276
      Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:58199 -> 147.185.221.18:61276
      Source: Network trafficSuricata IDS: 2825564 - Severity 1 - ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) : 192.168.2.4:58200 -> 147.185.221.18:61276
      Source: global trafficTCP traffic: 192.168.2.4:58197 -> 147.185.221.18:61276
      Source: Joe Sandbox ViewIP Address: 147.185.221.18 147.185.221.18
      Source: Joe Sandbox ViewASN Name: SALSGIVERUS SALSGIVERUS
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: unknownTCP traffic detected without corresponding DNS query: 147.185.221.18
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeWindow created: window name: CLIPBRDWNDCLASSJump to behavior

      E-Banking Fraud

      barindex
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000000.00000002.4137918645.00000000031B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: b34J4bxnmN.exe PID: 7352, type: MEMORYSTR

      System Summary

      barindex
      Source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
      Source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
      Source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
      Source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, type: UNPACKEDPEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
      Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
      Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
      Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
      Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
      Source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
      Source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess Stats: CPU usage > 49%
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeCode function: 0_2_064AB8400_2_064AB840
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeCode function: 0_2_064EB8700_2_064EB870
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeCode function: 0_2_064EF1900_2_064EF190
      Source: b34J4bxnmN.exe, 00000000.00000002.4136209898.00000000010F7000.00000004.00000010.00020000.00000000.sdmpBinary or memory string: OriginalFilenameUNKNOWN_FILET vs b34J4bxnmN.exe
      Source: b34J4bxnmN.exe, 00000000.00000000.1681019454.0000000000D54000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameWindowsUp.exeH vs b34J4bxnmN.exe
      Source: b34J4bxnmN.exe, 00000000.00000002.4136406285.000000000134E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs b34J4bxnmN.exe
      Source: b34J4bxnmN.exeBinary or memory string: OriginalFilenameWindowsUp.exeH vs b34J4bxnmN.exe
      Source: b34J4bxnmN.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
      Source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
      Source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
      Source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
      Source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, type: UNPACKEDPEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
      Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
      Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
      Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
      Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
      Source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
      Source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
      Source: classification engineClassification label: mal100.spre.phis.troj.evad.winEXE@4/2@0/1
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeFile created: C:\Users\user\AppData\Roaming\appJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeMutant created: NULL
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeMutant created: \Sessions\1\BaseNamedObjects\f7e6d24b4a113d9753558dfbb032c2ac
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7800:120:WilError_03
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeFile created: C:\Users\user\AppData\Local\Temp\FransescoPast.txtJump to behavior
      Source: b34J4bxnmN.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: b34J4bxnmN.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: b34J4bxnmN.exeReversingLabs: Detection: 52%
      Source: b34J4bxnmN.exeVirustotal: Detection: 53%
      Source: unknownProcess created: C:\Users\user\Desktop\b34J4bxnmN.exe "C:\Users\user\Desktop\b34J4bxnmN.exe"
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\Desktop\b34J4bxnmN.exe" "b34J4bxnmN.exe" ENABLE
      Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\Desktop\b34J4bxnmN.exe" "b34J4bxnmN.exe" ENABLEJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: mscoree.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: version.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: amsi.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: userenv.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: msasn1.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: gpapi.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: edputil.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: rsaenh.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeSection loaded: wbemcomn.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ifmon.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mprapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasmontr.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasapi32.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwpuclnt.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasman.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mfc42u.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasman.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: authfwcfg.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwpolicyiomgr.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: firewallapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dnsapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwbase.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dhcpcmonitor.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dot3cfg.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dot3api.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: onex.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: eappcfg.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ncrypt.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: eappprxy.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ntasn1.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwcfg.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: hnetmon.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: netshell.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nlaapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: netsetupapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: netiohlp.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dhcpcsvc.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: winnsi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nshhttp.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: httpapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nshipsec.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: userenv.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: activeds.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: polstore.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: winipsec.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: adsldpc.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nshwfp.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: cabinet.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: p2pnetsh.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: p2p.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rpcnsh.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: whhelper.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: winhttp.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wlancfg.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wlanapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wshelper.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wevtapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: peerdistsh.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wcmapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rmclient.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mobilenetworking.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: slc.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: sppc.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: gpapi.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ktmw32.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mprmsg.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeSection loaded: msasn1.dllJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
      Source: b34J4bxnmN.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
      Source: b34J4bxnmN.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
      Source: b34J4bxnmN.exeStatic file information: File size 9278464 > 1048576
      Source: b34J4bxnmN.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x8d0400
      Source: b34J4bxnmN.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

      Data Obfuscation

      barindex
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, Fransesco.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, Fransesco.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeCode function: 0_2_018B5745 push E9FFFFFFh; ret 0_2_018B574A
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeCode function: 0_2_018B5B45 push E9FFFFFFh; ret 0_2_018B5B4A
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeCode function: 0_2_061935E1 push ss; retf 0_2_061935E7
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeMemory allocated: 15D0000 memory reserve | memory write watchJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeMemory allocated: 31B0000 memory reserve | memory write watchJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeMemory allocated: 2F00000 memory reserve | memory write watchJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeThread delayed: delay time: 922337203685477Jump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeWindow / User API: threadDelayed 7165Jump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeWindow / User API: threadDelayed 2468Jump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeWindow / User API: foregroundWindowGot 773Jump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeWindow / User API: foregroundWindowGot 722Jump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exe TID: 7856Thread sleep time: -20291418481080494s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exe TID: 7872Thread sleep count: 7165 > 30Jump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exe TID: 7864Thread sleep count: 2468 > 30Jump to behavior
      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeThread delayed: delay time: 922337203685477Jump to behavior
      Source: b34J4bxnmN.exe, 00000000.00000002.4144372913.0000000005AF8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll[
      Source: netsh.exe, 00000004.00000002.2099177725.0000000000BD7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess token adjusted: DebugJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeMemory allocated: page read and write | page guardJump to behavior
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:33:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:18:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:04:55 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:24:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 15:57:01 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:02:35 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:39:15 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:08:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:43:28 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:16:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:02:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:13:41 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:10:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:50:36 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:04:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:16:55 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:21:45 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:18:10 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:41:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:02:29 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:11:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:36:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:08:09 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:22:08 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:54:35 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:24:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:04:36 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:12:49 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:07:21 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:24:16 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:02:01 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:30:45 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:10:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:09:39 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:17:29 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:52:46 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:17:47 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:50:54 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:59:42 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:29:19 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:38:04 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:58:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:46:08 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:38:28 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:40:01 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:57:10 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:44:39 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:33:17 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:49:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:28:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 07:21:41 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:59:28 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:33:35 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:16:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:26:10 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:33:17 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:37:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:08:09 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:42:36 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:06:31 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:16:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:05:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:25:13 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:13:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:33:44 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:06:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:56:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:40:47 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:41:48 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:08:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:05:39 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:21:21 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:19:26 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:51:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:29:20 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:23:19 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:50:49 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:57:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:39:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:50:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:27:22 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:16:22 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:27:59 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 04:51:08 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:26:28 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:22:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:55:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:57:11 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:22:41 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:40:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:44:39 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:15:11 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:13:18 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:20:54 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:28:04 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:17:48 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:34:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:45:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:22:03 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:18:45 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:53:16 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:55:47 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:31:19 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:32:16 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:08:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:05:30 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 04:19:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:58:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:20:20 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:59:10 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:44:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:13:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:27:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:22:57 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:47:09 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:31:09 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:41:01 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:14:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:38:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:28:27 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:45:16 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:20:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:53:57 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:04:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:55:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:25:40 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:44:34 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:15:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:26:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:25:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:24:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:08:52 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:54:30 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:29:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:06:54 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:35:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:22:04 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:35:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:26:57 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 04:54:36 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:10:47 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:25:40 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:07:08 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:03:09 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:46:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:02:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:04:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:33:47 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:35:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:11:39 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:06:39 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:28:31 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:04:47 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:55:32 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:38:32 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:16:22 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:17:19 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:54:03 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:43:18 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:15:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:02:24 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:34:15 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:19:22 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:11:29 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:26:18 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:21:36 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:24:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:20:29 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:36:59 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:50:30 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:51:31 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:41:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:08:43 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:13:29 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:26:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:59:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:42:40 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:52:09 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 04:49:18 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:55:27 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:32:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:07:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:00:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:46:41 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:42:20 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:35:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:14:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:13:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:39:48 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:30:40 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:36:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 07:57:13 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:06:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:58:50 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:33:46 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:28:41 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:21:58 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:15:54 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:28:54 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:39:01 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:35:01 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:46:17 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 05:11:35 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:05:29 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:31:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:49:03 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:44:04 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 04:59:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:02:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:13:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:04:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:05:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:29:16 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:46:27 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:47:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:04:22 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:16:47 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:59:03 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 04:53:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:21:03 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:39:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:50:10 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:14:40 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:09:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:53:58 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:26:52 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:27:34 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:06:45 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:26:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:41:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:52:19 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:34:27 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:53:20 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 06:00:50 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:45:40 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:55:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:14:54 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:14:19 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:35:13 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:22:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:25:09 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:50:11 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:02:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:28:26 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 04:18:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:45:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:23:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:17:09 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:46:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:32:54 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:04:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:19:49 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:31:35 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:40:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:30:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:59:35 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:09:11 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:03:49 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:02:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:49:47 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:37:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:59:32 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:42:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:08:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 04:50:29 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:48:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:10:11 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:01:08 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:00:13 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:31:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:05:31 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 04:35:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:00:46 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:34:42 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:38:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:58:13 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:06:59 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:43:46 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:32:49 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:53:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:35:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 15:57:52 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:41:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:02:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:46:13 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:28:48 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:12:31 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:55:40 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:56:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:02:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:55:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:54:17 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:33:48 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 15:56:58 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:15:31 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:30:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:45:18 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:21:10 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:46:49 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:17:10 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:04:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:38:46 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:23:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: Shell_traywnd+MostrarBarraDeTarefas
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:43:21 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:44:39 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:08:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 04:19:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:45:48 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:06:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:32:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:13:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:05:10 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:58:16 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:11:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:13:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:20:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:32:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:55:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:25:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:10:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:11:26 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:00:04 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:02:28 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:51:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:21:50 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:34:04 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:14:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:49:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:27:59 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:57:52 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:22:21 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:33:26 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:42:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:42:03 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:19:32 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:26:34 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:27:08 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:17:55 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:02:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:09:11 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:51:08 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:05:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:12:01 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:42:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:20:35 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:34:52 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:57:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:36:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:13:04 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:08:43 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:56:58 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:56:28 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:53:19 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:22:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:09:59 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:27:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:32:59 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:47:34 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:27:30 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:29:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:14:47 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:34:20 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:59:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:51:47 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:04:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:17:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:02:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:51:15 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:05:15 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:23:30 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:21:28 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:34:26 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:55:50 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:26:15 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:46:26 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 04:57:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:03:09 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:14:58 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:14:57 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:02:58 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:20:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:29:15 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:16:01 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:24:16 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:41:01 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:16:31 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:47:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:58:21 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:21:41 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:41:44 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:28:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:38:17 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:16:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:11:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:45:55 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:08:03 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:10:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:43:49 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:00:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:16:21 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:21:13 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:39:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:16:16 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:48:10 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:24:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:11:33 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:06:39 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:36:52 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:57:45 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 05:53:58 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:24:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:51:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:13:50 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 04:18:18 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:36:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:14:00 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:45:58 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:27:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:04:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:55:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:45:25 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:09:54 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:55:35 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:02:48 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 06:50:56 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:58:23 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:27:10 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:50:16 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 04:51:20 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:13:11 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:35:42 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:01:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 05:58:22 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:28:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:56:11 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:25:36 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:46:34 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:02:08 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:07:02 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:50:14 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:06:01 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:32:40 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:05:55 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:09:57 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:53:19 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:17:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:53:13 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:19:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:01:34 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:01:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:03:26 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:17:52 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:03:44 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:55:05 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:06:37 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:30:03 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 20:05:08 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 11:28:11 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:16:57 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:10:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:46:28 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:14:28 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:24:30 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:39:36 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:12:19 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 23:09:09 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 19:40:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:15:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:27:06 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 07:35:15 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 01:26:28 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/19 | 00:40:59 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:38:22 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:08:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:47:42 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:06:34 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 09:09:03 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:47:27 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:13:32 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 21:28:34 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:24:15 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 12:07:07 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 16:43:38 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:32:19 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:28:51 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:15:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 05:36:46 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 05:32:59 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 04:20:34 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 04:18:30 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:45:17 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 06:52:40 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 22:38:44 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 17:43:53 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/21 | 06:15:57 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 10:16:58 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/18 | 18:26:12 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 08:05:04 - Program Manager
      Source: b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000044F9000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, b34J4bxnmN.exe, 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/09/16 | 06:12:43 - Program Manager
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeQueries volume information: C:\Users\user\Desktop\b34J4bxnmN.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
      Source: C:\Windows\SysWOW64\netsh.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

      Lowering of HIPS / PFW / Operating System Security Settings

      barindex
      Source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, Fransesco.cs.Net Code: INS
      Source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, Fransesco.cs.Net Code: INS
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeRegistry value created: HKEY_CURRENT_USER\Environment SEE_MASK_NOZONECHECKSJump to behavior
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\Desktop\b34J4bxnmN.exe" "b34J4bxnmN.exe" ENABLE
      Source: C:\Users\user\Desktop\b34J4bxnmN.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\Desktop\b34J4bxnmN.exe" "b34J4bxnmN.exe" ENABLE

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000000.00000002.4137918645.00000000031B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: b34J4bxnmN.exe PID: 7352, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.5810000.1.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.5810000.1.raw.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.41f82a0.0.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 0.2.b34J4bxnmN.exe.41f82a0.0.raw.unpack, type: UNPACKEDPE
      Source: Yara matchFile source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000000.00000002.4137918645.00000000031B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: b34J4bxnmN.exe PID: 7352, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire Infrastructure11
      Replication Through Removable Media
      Windows Management Instrumentation1
      DLL Side-Loading
      2
      Process Injection
      1
      Masquerading
      OS Credential Dumping1
      Security Software Discovery
      Remote Services1
      Archive Collected Data
      1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
      DLL Side-Loading
      41
      Disable or Modify Tools
      LSASS Memory1
      Process Discovery
      Remote Desktop Protocol1
      Clipboard Data
      1
      Non-Standard Port
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)31
      Virtualization/Sandbox Evasion
      Security Account Manager31
      Virtualization/Sandbox Evasion
      SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook2
      Process Injection
      NTDS1
      Application Window Discovery
      Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
      Obfuscated Files or Information
      LSA Secrets1
      Peripheral Device Discovery
      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
      Software Packing
      Cached Domain Credentials12
      System Information Discovery
      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
      DLL Side-Loading
      DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      b34J4bxnmN.exe53%ReversingLabsWin32.Trojan.CrypterX
      b34J4bxnmN.exe53%VirustotalBrowse
      b34J4bxnmN.exe100%AviraHEUR/AGEN.1309702
      b34J4bxnmN.exe100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      147.185.221.18
      unknownUnited States
      12087SALSGIVERUStrue
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1511742
      Start date and time:2024-09-16 10:16:12 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 7m 40s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:default.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:7
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:b34J4bxnmN.exe
      renamed because original name is a hash value
      Original Sample Name:24aaa69f6e96ea14e0602d49d5c58a83.exe
      Detection:MAL
      Classification:mal100.spre.phis.troj.evad.winEXE@4/2@0/1
      EGA Information:
      • Successful, ratio: 100%
      HCA Information:Failed
      Cookbook Comments:
      • Found application associated with file extension: .exe
      • Override analysis time to 240s for sample files taking high CPU consumption
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
      • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtAllocateVirtualMemory calls found.
      TimeTypeDescription
      04:18:18API Interceptor132033x Sleep call for process: b34J4bxnmN.exe modified
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      147.185.221.1801koiHnedL.exeGet hashmaliciousNjratBrowse
        i231IEP3oh.exeGet hashmaliciousAsyncRATBrowse
          killer.exeGet hashmaliciousXWormBrowse
            system47.exeGet hashmaliciousXWormBrowse
              javaupdate.jarGet hashmaliciousDynamic StealerBrowse
                javaupdate.jarGet hashmaliciousDynamic StealerBrowse
                  LisectAVT_2403002C_149.exeGet hashmaliciousAsyncRATBrowse
                    LisectAVT_2403002C_28.exeGet hashmaliciousRemcosBrowse
                      sqjxHtZQi8.jpg.ps1Get hashmaliciousArrowRATBrowse
                        listafamilia_caipira.docGet hashmaliciousArrowRATBrowse
                          No context
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          SALSGIVERUS01koiHnedL.exeGet hashmaliciousNjratBrowse
                          • 147.185.221.18
                          nPIv2AODg2.exeGet hashmaliciousXWormBrowse
                          • 147.185.221.19
                          WLO9Pkkle0.exeGet hashmaliciousXWormBrowse
                          • 147.185.221.22
                          uUY8turU3x.exeGet hashmaliciousAsyncRAT, XWormBrowse
                          • 147.185.221.22
                          wB5Gc9RKzG.exeGet hashmaliciousXWormBrowse
                          • 147.185.221.22
                          Uhj9qfwbYG.exeGet hashmaliciousAsyncRAT, XWormBrowse
                          • 147.185.221.21
                          PjkFCWhi.exeGet hashmaliciousXWormBrowse
                          • 147.185.221.22
                          BootstrapperV3.0.exeGet hashmaliciousXWormBrowse
                          • 147.185.221.22
                          TRXLoader.exeGet hashmaliciousXWormBrowse
                          • 147.185.221.22
                          Bootstrapper.exeGet hashmaliciousXWormBrowse
                          • 147.185.221.22
                          No context
                          No context
                          Process:C:\Users\user\Desktop\b34J4bxnmN.exe
                          File Type:Unicode text, UTF-8 (with BOM) text, with no line terminators
                          Category:dropped
                          Size (bytes):5
                          Entropy (8bit):2.321928094887362
                          Encrypted:false
                          SSDEEP:3:1n:1
                          MD5:02B81B0CBE1FAAA1FA62D5FC876AB443
                          SHA1:D473CFE21FB1F188689415B0BDD239688F8FDDD9
                          SHA-256:E7E9E2C247BC872BACCE77661C78F001A17D70EE3130A9016A5818DA9DA00CDB
                          SHA-512:592AB5B200D4C560951CB70288DC1B7A562F0CBFAEE01CE03076B6934D537B88575C2E1E0FEDCC05DB95E6C224CA739923E7D74F9165E683F3FBAD7BBF641784
                          Malicious:false
                          Reputation:moderate, very likely benign file
                          Preview:.16
                          Process:C:\Windows\SysWOW64\netsh.exe
                          File Type:ASCII text, with CRLF line terminators
                          Category:dropped
                          Size (bytes):313
                          Entropy (8bit):4.971939296804078
                          Encrypted:false
                          SSDEEP:6:/ojfKsUTGN8Ypox42k9L+DbGMKeQE+vigqAZs2E+AYeDPO+Yswyha:wjPIGNrkHk9iaeIM6ADDPOHyha
                          MD5:689E2126A85BF55121488295EE068FA1
                          SHA1:09BAAA253A49D80C18326DFBCA106551EBF22DD6
                          SHA-256:D968A966EF474068E41256321F77807A042F1965744633D37A203A705662EC25
                          SHA-512:C3736A8FC7E6573FA1B26FE6A901C05EE85C55A4A276F8F569D9EADC9A58BEC507D1BB90DBF9EA62AE79A6783178C69304187D6B90441D82E46F5F56172B5C5C
                          Malicious:false
                          Reputation:high, very likely benign file
                          Preview:..IMPORTANT: Command executed successfully...However, "netsh firewall" is deprecated;..use "netsh advfirewall firewall" instead...For more information on using "netsh advfirewall firewall" commands..instead of "netsh firewall", see KB article 947709..at https://go.microsoft.com/fwlink/?linkid=121488 .....Ok.....
                          File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                          Entropy (8bit):5.656857908942536
                          TrID:
                          • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                          • Win32 Executable (generic) a (10002005/4) 49.78%
                          • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                          • Generic Win/DOS Executable (2004/3) 0.01%
                          • DOS Executable Generic (2002/1) 0.01%
                          File name:b34J4bxnmN.exe
                          File size:9'278'464 bytes
                          MD5:24aaa69f6e96ea14e0602d49d5c58a83
                          SHA1:d50b28c15f5a93a9e4679d3c43d88a17e7350f40
                          SHA256:3318d2024f5863942ba46235834bea85161a90219dbcb09bfadaf14f4811476f
                          SHA512:35f59bbd359371c9a584556899fa3990b2954a532b8d73e9b65282301b25bb3f32a218fcd19eba0aa473e5ab4cae21bba5f20584218f3800cc566534e007978c
                          SSDEEP:196608:eYzQO9kPmWdJGlvIGEBhQ7BP5TmoaiZMSW0G6JmJfLknzB:5zQ8kP9dgwXK7Lmo7ul8cTaB
                          TLSH:4D96C709FDF17E20CB9C053BA733D97C429361192F02D19FAA5A26452F5EBAACDC7409
                          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...?..f.............................#... ........@.. ....................................`................................
                          Icon Hash:06367b5b7d1e1f98
                          Entrypoint:0xcd231e
                          Entrypoint Section:.text
                          Digitally signed:false
                          Imagebase:0x400000
                          Subsystem:windows gui
                          Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                          DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                          Time Stamp:0x66E3B33F [Fri Sep 13 03:36:31 2024 UTC]
                          TLS Callbacks:
                          CLR (.Net) Version:
                          OS Version Major:4
                          OS Version Minor:0
                          File Version Major:4
                          File Version Minor:0
                          Subsystem Version Major:4
                          Subsystem Version Minor:0
                          Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                          Instruction
                          jmp dword ptr [00402000h]
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          add byte ptr [eax], al
                          NameVirtual AddressVirtual Size Is in Section
                          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                          IMAGE_DIRECTORY_ENTRY_IMPORT0x8d22cc0x4f.text
                          IMAGE_DIRECTORY_ENTRY_RESOURCE0x8d40000x8c00.rsrc
                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                          IMAGE_DIRECTORY_ENTRY_BASERELOC0x8de0000xc.reloc
                          IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                          IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                          IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                          .text0x20000x8d03240x8d0400fdf3f3d4cc95f21e0dd4182dac50f02cunknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                          .rsrc0x8d40000x8c000x8c0051ecbd7dd9bd1f30189aea279a4a5254False0.9709821428571429data7.8918163411654065IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                          .reloc0x8de0000xc0x2008e5e53a04c7173f92be615d27f935b89False0.044921875MacBinary, Mon Feb 6 07:28:16 2040 INVALID date, modified Mon Feb 6 07:28:16 2040 "\215"0.09800417566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                          NameRVASizeTypeLanguageCountryZLIB Complexity
                          RT_ICON0x8d44080x84b3PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced1.00017662123576
                          RT_GROUP_ICON0x8dc8c00x14data1.2
                          RT_VERSION0x8d41300x2d8data0.42445054945054944
                          RT_MANIFEST0x8dc8d80x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5469387755102041
                          DLLImport
                          mscoree.dll_CorExeMain
                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                          2024-09-16T10:17:49.335803+02002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.458197147.185.221.1861276TCP
                          2024-09-16T10:17:49.335803+02002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.458197147.185.221.1861276TCP
                          2024-09-16T10:17:55.378952+02002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.458197147.185.221.1861276TCP
                          2024-09-16T10:18:15.980739+02002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.458199147.185.221.1861276TCP
                          2024-09-16T10:18:15.980739+02002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.458199147.185.221.1861276TCP
                          2024-09-16T10:18:19.839943+02002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.458199147.185.221.1861276TCP
                          2024-09-16T10:19:03.934540+02002033132ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll)1192.168.2.458200147.185.221.1861276TCP
                          2024-09-16T10:19:03.934540+02002021176ET MALWARE Bladabindi/njRAT CnC Command (ll)1192.168.2.458200147.185.221.1861276TCP
                          2024-09-16T10:19:03.996125+02002825564ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act)1192.168.2.458200147.185.221.1861276TCP
                          TimestampSource PortDest PortSource IPDest IP
                          Sep 16, 2024 10:17:49.153800964 CEST5819761276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:17:49.158596992 CEST6127658197147.185.221.18192.168.2.4
                          Sep 16, 2024 10:17:49.158684015 CEST5819761276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:17:49.335803032 CEST5819761276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:17:49.341955900 CEST6127658197147.185.221.18192.168.2.4
                          Sep 16, 2024 10:17:49.342031002 CEST5819761276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:17:49.348248959 CEST6127658197147.185.221.18192.168.2.4
                          Sep 16, 2024 10:17:55.378952026 CEST5819761276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:17:55.384298086 CEST6127658197147.185.221.18192.168.2.4
                          Sep 16, 2024 10:18:13.961980104 CEST6127658197147.185.221.18192.168.2.4
                          Sep 16, 2024 10:18:13.962049007 CEST5819761276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:18:15.974567890 CEST5819761276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:18:15.974977970 CEST5819961276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:18:15.979542017 CEST6127658197147.185.221.18192.168.2.4
                          Sep 16, 2024 10:18:15.979829073 CEST6127658199147.185.221.18192.168.2.4
                          Sep 16, 2024 10:18:15.979899883 CEST5819961276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:18:15.980739117 CEST5819961276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:18:15.985563040 CEST6127658199147.185.221.18192.168.2.4
                          Sep 16, 2024 10:18:15.985738039 CEST5819961276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:18:15.990516901 CEST6127658199147.185.221.18192.168.2.4
                          Sep 16, 2024 10:18:19.839942932 CEST5819961276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:18:19.845257998 CEST6127658199147.185.221.18192.168.2.4
                          Sep 16, 2024 10:19:01.883557081 CEST6127658199147.185.221.18192.168.2.4
                          Sep 16, 2024 10:19:01.883785009 CEST5819961276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:19:03.913245916 CEST5819961276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:19:03.913741112 CEST5820061276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:19:03.918188095 CEST6127658199147.185.221.18192.168.2.4
                          Sep 16, 2024 10:19:03.918574095 CEST6127658200147.185.221.18192.168.2.4
                          Sep 16, 2024 10:19:03.918658018 CEST5820061276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:19:03.934540033 CEST5820061276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:19:03.939436913 CEST6127658200147.185.221.18192.168.2.4
                          Sep 16, 2024 10:19:03.939516068 CEST5820061276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:19:03.944346905 CEST6127658200147.185.221.18192.168.2.4
                          Sep 16, 2024 10:19:03.996124983 CEST5820061276192.168.2.4147.185.221.18
                          Sep 16, 2024 10:19:04.000920057 CEST6127658200147.185.221.18192.168.2.4
                          TimestampSource PortDest PortSource IPDest IP
                          Sep 16, 2024 10:17:24.576581955 CEST53643221.1.1.1192.168.2.4

                          Click to jump to process

                          Click to jump to process

                          Click to dive into process behavior distribution

                          Click to jump to process

                          Target ID:0
                          Start time:04:17:03
                          Start date:16/09/2024
                          Path:C:\Users\user\Desktop\b34J4bxnmN.exe
                          Wow64 process (32bit):true
                          Commandline:"C:\Users\user\Desktop\b34J4bxnmN.exe"
                          Imagebase:0x480000
                          File size:9'278'464 bytes
                          MD5 hash:24AAA69F6E96EA14E0602D49D5C58A83
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Yara matches:
                          • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                          • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, Author: unknown
                          • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, Author: Florian Roth
                          • Rule: Njrat, Description: detect njRAT in memory, Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
                          • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: 00000000.00000002.4142920165.0000000005810000.00000004.08000000.00040000.00000000.sdmp, Author: ditekSHen
                          • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                          • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                          • Rule: Njrat, Description: detect njRAT in memory, Source: 00000000.00000002.4140324970.00000000041B9000.00000004.00000800.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
                          • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000000.00000002.4137918645.00000000031B1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                          Reputation:low
                          Has exited:false

                          Target ID:4
                          Start time:04:17:45
                          Start date:16/09/2024
                          Path:C:\Windows\SysWOW64\netsh.exe
                          Wow64 process (32bit):true
                          Commandline:netsh firewall add allowedprogram "C:\Users\user\Desktop\b34J4bxnmN.exe" "b34J4bxnmN.exe" ENABLE
                          Imagebase:0x1560000
                          File size:82'432 bytes
                          MD5 hash:4E89A1A088BE715D6C946E55AB07C7DF
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Target ID:5
                          Start time:04:17:45
                          Start date:16/09/2024
                          Path:C:\Windows\System32\conhost.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                          Imagebase:0x7ff7699e0000
                          File size:862'208 bytes
                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Reset < >

                            Execution Graph

                            Execution Coverage:3.4%
                            Dynamic/Decrypted Code Coverage:100%
                            Signature Coverage:35.3%
                            Total number of Nodes:17
                            Total number of Limit Nodes:0
                            execution_graph 11319 61af8b8 11320 61af8fe 11319->11320 11323 61afa98 11320->11323 11326 61afb00 DuplicateHandle 11323->11326 11327 61af9eb 11326->11327 11328 64eb870 11329 64eb894 11328->11329 11332 64eead0 11329->11332 11330 64ebc23 11333 64eeafb 11332->11333 11334 64eebea 11333->11334 11336 64ef190 11333->11336 11334->11330 11337 64ef1f8 CreateProcessW 11336->11337 11339 64ef399 11337->11339 11340 64eef10 11341 64eef51 CloseHandle 11340->11341 11342 64eef84 11341->11342

                            Control-flow Graph

                            • Executed
                            • Not Executed
                            control_flow_graph 0 64eb870-64eb89b 2 64eb923-64eb92b 0->2 3 64eb8a1-64eb921 0->3 4 64eb937-64eb94b 2->4 3->2 30 64eb92d 3->30 5 64ebb1c-64ebc72 call 64eead0 4->5 6 64eb951-64eb98e 4->6 43 64ebe0c-64ebe20 5->43 44 64ebc78-64ebdd1 5->44 18 64eb9c0-64ebadb 6->18 19 64eb990-64eb9b9 6->19 18->5 19->18 30->4 46 64ebe26-64ebf36 43->46 47 64ebf71-64ebf85 43->47 44->43 46->47 50 64ebfd7-64ebfeb 47->50 51 64ebf87-64ebf9c 47->51 53 64ebfed-64ebff8 50->53 54 64ec033-64ec047 50->54 51->50 53->54 55 64ec04d-64ec15d 54->55 56 64ec198-64ec1ac 54->56 55->56 60 64ec2ce-64ec2e2 56->60 61 64ec1b2-64ec1c6 56->61 66 64ec2e8-64ec52a 60->66 67 64ec571-64ec585 60->67 64 64ec1c8-64ec1cf 61->64 65 64ec1d1-64ec1e5 61->65 72 64ec249-64ec25d 64->72 74 64ec1e7-64ec1ee 65->74 75 64ec1f0-64ec204 65->75 66->67 76 64ec5ea-64ec5fe 67->76 77 64ec587-64ec5a3 67->77 85 64ec25f-64ec276 72->85 86 64ec278-64ec284 72->86 74->72 79 64ec20f-64ec223 75->79 80 64ec206-64ec20d 75->80 82 64ec64d-64ec661 76->82 83 64ec600-64ec606 76->83 77->76 90 64ec22e-64ec242 79->90 91 64ec225-64ec22c 79->91 80->72 92 64ec6aa-64ec6be 82->92 93 64ec663 82->93 83->82 94 64ec290 85->94 86->94 90->72 100 64ec244-64ec246 90->100 91->72 97 64ec6c4-64ec709 92->97 98 64ec755-64ec769 92->98 93->92 94->60 97->98 106 64ec76f-64ecaf8 98->106 107 64ecb49-64ecb5d 98->107 100->72 485 64ecafc call 64ef6e8 106->485 486 64ecafa 106->486 108 64ecc33-64ecc47 107->108 109 64ecb63-64ecbec 107->109 115 64ecc4d-64ecdc0 108->115 116 64ece07-64ece1b 108->116 109->108 115->116 120 64ecf81-64ecf95 116->120 121 64ece21-64ecf3a 116->121 131 64ed0fb-64ed10f 120->131 132 64ecf9b-64ed0b4 120->132 121->120 138 64ed275-64ed289 131->138 139 64ed115-64ed22e 131->139 132->131 143 64ed3ef-64ed403 138->143 144 64ed28f-64ed3a8 138->144 139->138 152 64ed569-64ed57d 143->152 153 64ed409-64ed522 143->153 144->143 159 64ed6e3-64ed6f7 152->159 160 64ed583-64ed69c 152->160 153->152 166 64ed85d-64ed871 159->166 167 64ed6fd-64ed816 159->167 160->159 177 64ed9d7-64ed9eb 166->177 178 64ed877-64ed990 166->178 167->166 185 64edb51-64edb65 177->185 186 64ed9f1-64edb0a 177->186 178->177 195 64edb6b-64edbb2 185->195 196 64edcf6-64edd0a 185->196 186->185 324 64edc7d-64edc9f 195->324 206 64ede60-64ede74 196->206 207 64edd10-64edd2f 196->207 220 64edfcd-64edfe1 206->220 221 64ede7a-64edf86 206->221 243 64edde7-64ede09 207->243 228 64ee13a-64ee14e 220->228 229 64edfe7-64ee0f3 220->229 221->220 237 64ee2a7-64ee2d1 228->237 238 64ee154-64ee260 228->238 229->228 269 64ee379-64ee38d 237->269 270 64ee2d7-64ee332 237->270 238->237 248 64ede0f 243->248 249 64edd34-64edd43 243->249 248->206 266 64edd49-64edd7d 249->266 267 64ede11 249->267 356 64edd7f-64eddc7 266->356 357 64eddd2-64edddf 266->357 284 64ede16-64ede5e 267->284 273 64ee393-64ee3a3 269->273 274 64ee481-64ee495 269->274 270->269 322 64ee3ae-64ee43a 273->322 291 64ee49b-64ee59f 274->291 292 64ee5e6-64ee5fa 274->292 284->206 291->292 301 64ee8ca-64ee8de 292->301 302 64ee600-64ee65b 292->302 312 64ee8e4-64ee98e 301->312 313 64ee9d5-64ee9db 301->313 413 64ee6e1-64ee716 302->413 414 64ee661-64ee691 302->414 312->313 322->274 344 64edbb7-64edbc6 324->344 345 64edca5 324->345 350 64edbcc-64edc75 344->350 351 64edca7 344->351 345->196 379 64edcac-64edcf4 350->379 487 64edc77 350->487 351->379 356->357 357->284 359 64edde1 357->359 359->243 379->196 493 64ee71c-64ee814 413->493 494 64ee819-64ee8c4 413->494 488 64ee6dc 414->488 489 64ee693-64ee6bd 414->489 495 64ecb02 485->495 486->495 487->324 488->301 489->488 493->301 494->301 495->107
                            Strings
                            Memory Dump Source
                            • Source File: 00000000.00000002.4145077897.00000000064E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 064E0000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_0_2_64e0000_b34J4bxnmN.jbxd
                            Similarity
                            • API ID:
                            • String ID: @
                            • API String ID: 0-2766056989
                            • Opcode ID: 3118d268a69a36e1d2bd5d572174aef2e05fae6aa8ece7506e20cd27be143c52
                            • Instruction ID: f852e3cad392f7ee390aa09b1bebe4b64649d6958ddda3c1e98353bf52702b9d
                            • Opcode Fuzzy Hash: 3118d268a69a36e1d2bd5d572174aef2e05fae6aa8ece7506e20cd27be143c52
                            • Instruction Fuzzy Hash: 90333D74A01228CFDB65DF24D994BA9BBB2FB88305F1041D9D819A73A1DB35AEC1CF41

                            Control-flow Graph

                            • Executed
                            • Not Executed
                            control_flow_graph 556 64ef190-64ef204 558 64ef20f-64ef216 556->558 559 64ef206-64ef20c 556->559 560 64ef218-64ef21e 558->560 561 64ef221-64ef228 558->561 559->558 560->561 562 64ef22a-64ef246 561->562 563 64ef247-64ef24b 561->563 562->563 564 64ef24d-64ef263 563->564 565 64ef26b-64ef27b 563->565 564->565 566 64ef27d-64ef299 565->566 567 64ef29a-64ef29e 565->567 566->567 568 64ef2bf-64ef2d8 567->568 569 64ef2a0-64ef2b7 567->569 570 64ef2da-64ef2e3 568->570 571 64ef2e6-64ef2ef 568->571 569->568 570->571 572 64ef30a-64ef30e 571->572 573 64ef2f1-64ef308 571->573 574 64ef329-64ef33d 572->574 575 64ef310-64ef321 572->575 573->572 576 64ef33f 574->576 577 64ef342-64ef397 CreateProcessW 574->577 575->574 576->577 578 64ef399-64ef39f 577->578 579 64ef3a0-64ef3d1 577->579 578->579 582 64ef3e6-64ef3ea 579->582 583 64ef3d3-64ef3d7 579->583 585 64ef3ff-64ef403 582->585 586 64ef3ec-64ef3f0 582->586 583->582 584 64ef3d9-64ef3dc 583->584 584->582 587 64ef418-64ef41c 585->587 588 64ef405-64ef409 585->588 586->585 589 64ef3f2-64ef3f5 586->589 591 64ef41e-64ef42a 587->591 592 64ef42d 587->592 588->587 590 64ef40b-64ef40e 588->590 589->585 590->587 591->592
                            APIs
                            • CreateProcessW.KERNELBASE(?,?,00000000,00000000,?,?,?,00000000,00000000,?), ref: 064EF381
                            Memory Dump Source
                            • Source File: 00000000.00000002.4145077897.00000000064E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 064E0000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_0_2_64e0000_b34J4bxnmN.jbxd
                            Similarity
                            • API ID: CreateProcess
                            • String ID:
                            • API String ID: 963392458-0
                            • Opcode ID: c6a89d9187dfda2e8f53360b23ad37af6112e25ac57c7b5f4629aa296469d2a9
                            • Instruction ID: 61f4c98c8f3b0ca377f2a78a5f1dd5cdad05a79045735c0485962bef0b4db907
                            • Opcode Fuzzy Hash: c6a89d9187dfda2e8f53360b23ad37af6112e25ac57c7b5f4629aa296469d2a9
                            • Instruction Fuzzy Hash: A291F571D00749DFDB65CFA9C8847DEBBB2AF88301F24812AE818A7250D770A949CF91

                            Control-flow Graph

                            • Executed
                            • Not Executed
                            control_flow_graph 594 61afb00-61afb9a DuplicateHandle 595 61afb9c-61afba2 594->595 596 61afba3-61afbc0 594->596 595->596
                            APIs
                            • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 061AFB87
                            Memory Dump Source
                            • Source File: 00000000.00000002.4144687732.0000000006190000.00000040.00000800.00020000.00000000.sdmp, Offset: 06190000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_0_2_6190000_b34J4bxnmN.jbxd
                            Similarity
                            • API ID: DuplicateHandle
                            • String ID:
                            • API String ID: 3793708945-0
                            • Opcode ID: a3d823a70a8a968193ec593b5bcb6138355cc630ebbb3568e965fda6373d9e01
                            • Instruction ID: 8e3dc11b32c5aeb06b4d3670c66dc489bbee77970455709e01b7ee1af327627c
                            • Opcode Fuzzy Hash: a3d823a70a8a968193ec593b5bcb6138355cc630ebbb3568e965fda6373d9e01
                            • Instruction Fuzzy Hash: E921FFB5D002089FDB10CFAAD984ADEBBF8EB48320F14811AE918A3350C375A945CFA4

                            Control-flow Graph

                            • Executed
                            • Not Executed
                            control_flow_graph 653 64ab6c8-64ab6ef 654 64ab711-64ab71d 653->654 655 64ab723-64ab72d 654->655 656 64ab7f4-64ab7fe 654->656 657 64ab6f1-64ab6f4 655->657 658 64ab6fd-64ab70f 657->658 659 64ab6f6 657->659 658->657 659->654 659->658 661 64ab778-64ab77c 659->661 662 64ab789-64ab791 659->662 663 64ab769-64ab775 659->663 664 64ab7d9-64ab7dd 659->664 665 64ab74e 659->665 666 64ab72f-64ab73e 659->666 667 64ab77f-64ab784 659->667 668 64ab7bd-64ab7bf 659->668 669 64ab750-64ab755 659->669 670 64ab757 659->670 661->667 672 64ab798-64ab79a 662->672 673 64ab793-64ab797 662->673 663->661 664->656 671 64ab7df-64ab7e7 664->671 665->669 675 64ab740 666->675 676 64ab747-64ab74c 666->676 667->657 677 64ab7cd-64ab7d6 668->677 678 64ab7c1-64ab7c7 668->678 669->657 679 64ab760-64ab767 670->679 671->656 680 64ab7e9-64ab7ef 671->680 681 64ab79c 672->681 682 64ab7a6-64ab7ad 672->682 673->672 683 64ab745 675->683 676->683 684 64ab7cb 678->684 685 64ab7c9 678->685 679->657 680->657 686 64ab7a1 681->686 682->656 687 64ab7af-64ab7bb 682->687 683->657 684->677 685->677 686->657 687->686
                            Strings
                            Memory Dump Source
                            • Source File: 00000000.00000002.4144974008.00000000064A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 064A0000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_0_2_64a0000_b34J4bxnmN.jbxd
                            Similarity
                            • API ID:
                            • String ID: $^q
                            • API String ID: 0-388095546
                            • Opcode ID: e18e3dacfe94ee56b30745a68ad00c578efcd2cf72fd70ed47d90981641607ca
                            • Instruction ID: ab83b8c49c3185e9a3006e095ffd79fa5ab5e2040345e2e2af063dfce0d7e8bb
                            • Opcode Fuzzy Hash: e18e3dacfe94ee56b30745a68ad00c578efcd2cf72fd70ed47d90981641607ca
                            • Instruction Fuzzy Hash: 0031B034A08359AFDB919BAE84406BABBF0EB15311F04806BE565C63C1D2749951CBA2

                            Control-flow Graph

                            • Executed
                            • Not Executed
                            control_flow_graph 688 64eef10-64eef82 CloseHandle 690 64eef8b-64eefa8 688->690 691 64eef84-64eef8a 688->691 691->690
                            APIs
                            Memory Dump Source
                            • Source File: 00000000.00000002.4145077897.00000000064E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 064E0000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_0_2_64e0000_b34J4bxnmN.jbxd
                            Similarity
                            • API ID: CloseHandle
                            • String ID:
                            • API String ID: 2962429428-0
                            • Opcode ID: 3012a663167c1da22dfcbf7ad05b5208b91ab25c4819a800a46aea70fa0ff911
                            • Instruction ID: ac8ff659227098b3f6b91c7b1db1fe71162f42d8ba9a4c474b0d5acf6647d759
                            • Opcode Fuzzy Hash: 3012a663167c1da22dfcbf7ad05b5208b91ab25c4819a800a46aea70fa0ff911
                            • Instruction Fuzzy Hash: 6A1143B5900209CFCB20DF9AD844BDEFBF4EB48324F20841AD418A7350C779A945CFA4

                            Control-flow Graph

                            • Executed
                            • Not Executed
                            control_flow_graph 694 61cfbf8-61cfcc8 709 61cfccf-61cfd7d 694->709 713 61cfd7f-61cfda9 709->713 714 61cfdb0-61cfddf 709->714 713->714 718 61cfe07-61cfe36 714->718 719 61cfde1-61cfe01 714->719 723 61cfe5e-61cfe83 718->723 724 61cfe38-61cfe58 718->724 719->718 728 61cfeea-61cfef0 723->728 729 61cfe85-61cfe89 723->729 724->723 731 61cfef7-61cfefe 728->731 732 61cfef2 728->732 729->728 730 61cfe8b-61cfee7 729->730 730->728 732->731
                            Memory Dump Source
                            • Source File: 00000000.00000002.4144842086.00000000061C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 061C0000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_0_2_61c0000_b34J4bxnmN.jbxd
                            Similarity
                            • API ID:
                            • String ID:
                            • API String ID:
                            • Opcode ID: a6c302e829d90e60dd51ab7ed999686d6b28d8108df378f385bba4941dcf2fbe
                            • Instruction ID: 1c2bf6ec4df558e37960c36658560996b43104c0b228c50ae7c9b053a3635a8e
                            • Opcode Fuzzy Hash: a6c302e829d90e60dd51ab7ed999686d6b28d8108df378f385bba4941dcf2fbe
                            • Instruction Fuzzy Hash: 9FA16335A10609CFCB04DF6DC48499DBBB1FF89314B1186A9E905AB366EB70ED85CF90

                            Control-flow Graph

                            • Executed
                            • Not Executed
                            control_flow_graph 761 154d01c-154d02e 762 154d034 761->762 763 154d0bd-154d0c4 761->763 764 154d036-154d042 762->764 763->764 766 154d048-154d06a 764->766 767 154d0c9-154d0ce 764->767 768 154d0d3-154d0e8 766->768 769 154d06c-154d086 766->769 767->766 773 154d09f-154d0a7 768->773 772 154d08e-154d09d 769->772 772->773 774 154d0f5 772->774 775 154d0a9-154d0ba 773->775 776 154d0ea-154d0f3 773->776 776->775
                            Memory Dump Source
                            • Source File: 00000000.00000002.4137050345.000000000154D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0154D000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_0_2_154d000_b34J4bxnmN.jbxd
                            Similarity
                            • API ID:
                            • String ID:
                            • API String ID:
                            • Opcode ID: d0f2850e61a50ea372a3ac79294fdf88b8fb16212374e44257e4924d7a3ea871
                            • Instruction ID: 59779d206ab0971944b5c1cb7bd2520f71584f18c70210f72784e0c0c5705694
                            • Opcode Fuzzy Hash: d0f2850e61a50ea372a3ac79294fdf88b8fb16212374e44257e4924d7a3ea871
                            • Instruction Fuzzy Hash: A1210071604200DFCB15DF98D984B2ABBB5FB94318F20C96DD80E4F256D33AD446CA61

                            Control-flow Graph

                            • Executed
                            • Not Executed
                            control_flow_graph 778 154d006-154d02e 779 154d034 778->779 780 154d0bd-154d0c4 778->780 781 154d036-154d042 779->781 780->781 783 154d048-154d06a 781->783 784 154d0c9-154d0ce 781->784 785 154d0d3-154d0e8 783->785 786 154d06c-154d086 783->786 784->783 790 154d09f-154d0a7 785->790 789 154d08e-154d09d 786->789 789->790 791 154d0f5 789->791 792 154d0a9-154d0ba 790->792 793 154d0ea-154d0f3 790->793 793->792
                            Memory Dump Source
                            • Source File: 00000000.00000002.4137050345.000000000154D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0154D000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_0_2_154d000_b34J4bxnmN.jbxd
                            Similarity
                            • API ID:
                            • String ID:
                            • API String ID:
                            • Opcode ID: 41e84cba84804d9039f37e384489e195bc9fc5d6162cef47cdb92d73bc79016e
                            • Instruction ID: 3966d27414dbdae97ce26815676e8fce2a3aa6fd06d7803ba2653a8bd4bc0cbe
                            • Opcode Fuzzy Hash: 41e84cba84804d9039f37e384489e195bc9fc5d6162cef47cdb92d73bc79016e
                            • Instruction Fuzzy Hash: 602192755093808FDB13CF64D994715BF71FB46218F28C5DAD8498F2A7C33A980ACB62

                            Control-flow Graph

                            • Executed
                            • Not Executed
                            control_flow_graph 808 64ab840-64ab84d 809 64ab84f-64ab851 808->809 810 64ab856-64ab866 808->810 811 64abaf5-64abafc 809->811 812 64ab868 810->812 813 64ab86d-64ab87d 810->813 812->811 815 64abadc-64abaea 813->815 816 64ab883-64ab891 813->816 819 64abafd-64abb76 815->819 821 64abaec-64abaee 815->821 816->819 820 64ab897 816->820 820->819 822 64ab928-64ab949 820->822 823 64ab94e-64ab96f 820->823 824 64aba8f-64abaaa 820->824 825 64abaac-64abace 820->825 826 64ab902-64ab923 820->826 827 64aba61-64aba8d 820->827 828 64ab9c7-64ab9ef 820->828 829 64ab99a-64ab9c2 820->829 830 64ab8db-64ab8fd 820->830 831 64ab89e-64ab8b0 820->831 832 64abad0-64abada 820->832 833 64aba36-64aba5c 820->833 834 64ab974-64ab995 820->834 835 64ab9f4-64aba31 820->835 836 64ab8b5-64ab8d6 820->836 821->811 822->811 823->811 824->811 825->811 826->811 827->811 828->811 829->811 830->811 831->811 832->811 833->811 834->811 835->811 836->811
                            Strings
                            Memory Dump Source
                            • Source File: 00000000.00000002.4144974008.00000000064A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 064A0000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_0_2_64a0000_b34J4bxnmN.jbxd
                            Similarity
                            • API ID:
                            • String ID: V$Xbq$$^q
                            • API String ID: 0-4277496983
                            • Opcode ID: 582a19f5c339660cf0844ddcae560affff92adc52b61e3259328061a39d0a92c
                            • Instruction ID: 51d4c8991e6c1d8e590bae8fd2acbca8ee2a1cf71902fd5056ed377baa089320
                            • Opcode Fuzzy Hash: 582a19f5c339660cf0844ddcae560affff92adc52b61e3259328061a39d0a92c
                            • Instruction Fuzzy Hash: 9481A174B003189BDB58EF7985A467E7BB7BFC8710B05842EE406EB398CE3498069791