Click to jump to signature section
Source: nQBmwBd90o.exe, 00000000.00000000.1664507002.0000000000E1E000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenamediscord.exe> vs nQBmwBd90o.exe |
Source: nQBmwBd90o.exe, 00000000.00000002.1668178797.00000000013BE000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs nQBmwBd90o.exe |
Source: nQBmwBd90o.exe, 00000001.00000002.2932477946.0000000000FFE000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs nQBmwBd90o.exe |
Source: nQBmwBd90o.exe | Binary or memory string: OriginalFilenamediscord.exe> vs nQBmwBd90o.exe |
Source: nQBmwBd90o.exe.0.dr | Binary or memory string: OriginalFilenamediscord.exe> vs nQBmwBd90o.exe |
Source: nQBmwBd90o.exe, Encryption.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: nQBmwBd90o.exe.0.dr, Encryption.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Mutant created: NULL |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Mutant created: \Sessions\1\BaseNamedObjects\update_discord_nd8912d-admin |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5180:120:WilError_03 |
Source: unknown | Process created: C:\Users\user\Desktop\nQBmwBd90o.exe "C:\Users\user\Desktop\nQBmwBd90o.exe" | |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process created: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe "C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe" | |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process created: C:\Windows\SysWOW64\schtasks.exe "schtasks.exe" /Create /TN "update_blender" /XML "C:\Users\user\AppData\Local\Temp\tmp86AB.tmp" /F | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process created: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe "C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process created: C:\Windows\SysWOW64\schtasks.exe "schtasks.exe" /Create /TN "update_blender" /XML "C:\Users\user\AppData\Local\Temp\tmp86AB.tmp" /F | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: nQBmwBd90o.exe, DllHandler.cs | .Net Code: DllNodeHandler System.Reflection.Assembly.Load(byte[]) |
Source: nQBmwBd90o.exe, DllHandler.cs | .Net Code: DllNodeHandler |
Source: nQBmwBd90o.exe.0.dr, DllHandler.cs | .Net Code: DllNodeHandler System.Reflection.Assembly.Load(byte[]) |
Source: nQBmwBd90o.exe.0.dr, DllHandler.cs | .Net Code: DllNodeHandler |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Memory allocated: 1640000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Memory allocated: 30F0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe | Memory allocated: 50F0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Memory allocated: 2E30000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Memory allocated: 2E60000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Memory allocated: 4E60000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Memory allocated: 710000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Memory allocated: 24C0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe | Memory allocated: B20000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\nQBmwBd90o.exe TID: 6908 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe TID: 7096 | Thread sleep time: -27670116110564310s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe TID: 932 | Thread sleep count: 1506 > 30 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe TID: 932 | Thread sleep count: 8357 > 30 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe TID: 1068 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: nQBmwBd90o.exe, 00000000.00000002.1668178797.00000000013F5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}h |
Source: nQBmwBd90o.exe, 00000001.00000002.2932477946.0000000001086000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: Yara match | File source: nQBmwBd90o.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.nQBmwBd90o.exe.e10000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000000.1664494365.0000000000E12000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.1668178797.00000000013F5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: nQBmwBd90o.exe PID: 6836, type: MEMORYSTR |
Source: Yara match | File source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe, type: DROPPED |
Source: Yara match | File source: nQBmwBd90o.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.nQBmwBd90o.exe.e10000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000000.1664494365.0000000000E12000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.1668178797.00000000013F5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: nQBmwBd90o.exe PID: 6836, type: MEMORYSTR |
Source: Yara match | File source: C:\Users\user\AppData\Roaming\XenoManager\nQBmwBd90o.exe, type: DROPPED |