Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6596D7000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://.css |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6596D7000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://.jpg |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/1423136 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/1423136Disables |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/1452 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/1452Bug |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/2152 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/2152On |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/3246 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/3246On |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/3682 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/3682There |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/5007 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/5007Disable |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/5658 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/5658Even |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/5750 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/5750Set |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/6041 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/6041Force-enable |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/7036 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/7036Enable |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/7279 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/7279Emulate |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/7724 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/7724Disable |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/7760 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/7760Write |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/7761 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://anglebug.com/7761Check |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://bugreports.qt.io/ |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://bugreports.qt.io/_q_receiveReplyensureClientPrefaceSentMicrosoft-IIS/4.Microsoft-IIS/5.Netsca |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://crbug.com/941620 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://crbug.com/941620Some |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0 |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0 |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://crl.sectigo.com/SectigoPublicTimeStampingCAR36.crl0z |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://crl.sectigo.com/SectigoPublicTimeStampingRootR46.crl0 |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://crt.sectigo.com/SectigoPublicTimeStampingCAR36.crt0# |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://crt.sectigo.com/SectigoPublicTimeStampingRootR46.p7c0# |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6596D7000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://html4/loose.dtd |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.sectigo.com0 |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0? |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0Digitized |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.ascendercorp.com/http://www.ascendercorp.com/typedesigners.htmlLicensed |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01x |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.phreedom.org/md5) |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.phreedom.org/md5)08:27 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-time |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-timehttp://www.webrtc.org/experiments/rtp-h |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-send-time |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/color-space |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/generic-frame-descriptor-00 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/inband-cn |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/inband-cnurn:ietf:params:rtp-hdrext:csrc-audio-level |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/playout-delay |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/transport-wide-cc-02 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-content-type |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-frame-tracking-id |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-layers-allocation00 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-timing |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.winimage.com/zLibDll |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://%1/%2tokenize/cardtgb.smart-glocal.com/cds/v1expiration_yearexpiration_monthtgb-playground.s |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://ads.telegram.orgTelegram |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://anglebug.com/7246 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://anglebug.com/7246Force |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://aomediacodec.github.io/av1-rtp-spec/#dependency-descriptor-rtp-header-extension |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://api.mapbox.com/mapbox-gl-js/v3.4.0/mapbox-gl.css |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://api.mapbox.com/mapbox-gl-js/v3.4.0/mapbox-gl.js |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://api.mapbox.com/search/geocode/v6/reverse?longitude=%1&latitude=%2&language=%3&access_token=% |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://chromium.googlesource.com/angle/angle/ |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://core.telegram.org/api |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://core.telegram.org/apihttps://promote.telegram.org |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://crbug.com/1053756 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://crbug.com/1053756ICE |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://crbug.com/593024 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://crbug.com/593024Copying |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://crbug.com/650547 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://crbug.com/650547Using |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://crbug.com/655534 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://crbug.com/655534Using |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp, Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://desktop.telegram.org |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://desktop.telegram.org/changelog |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://desktop.telegram.orghttps://snapcraft.io/telegram-desktophttps://flathub.org/apps/details/or |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://flathub.org/apps/details/org.telegram.desktop |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://github.com/davelab6/Roboto-ClassicThis |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://github.com/rastikerdar/vazirmatn)Vazirmatn |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://github.com/telegramdesktop/tdesktop |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://github.com/telegramdesktop/tdesktop/blob/master/LICENSE |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://github.com/telegramdesktop/tdesktop/blob/master/LICENSEdeThe |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://github.com/telegramdesktop/tdesktopGNU |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://instagram.com/ |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://instagram.com/explore/tags/ |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://issuetracker.google.com/220069903 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF6597D8000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://issuetracker.google.com/220069903Force |
Source: Unconfirmed 103549.crdownload.0.dr |
String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp, Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://maps.google.com/maps?q= |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://promote.telegram.org |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://promote.telegram.org/guidelines |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://scripts.sil.org/OFLhttps://scripts.sil.org/OFL |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://scripts.sil.org/OFLhttps://scripts.sil.org/OFLVazirmatn |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://sectigo.com/CPS0 |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://snapcraft.io/telegram-desktop |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://ss3.4sqi.net/img/categories_v2/ |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://streams.videolan.org/upload/ |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://t.me |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp, Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://t.me/ |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://t.me/$ |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://t.me/$premium.promo_screen_showpremium.promo_screen_acceptpremium_promo_ordersourceprofile_: |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://t.me/TelegramTipsWarningYou |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://t.me/c/%1/%2 |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://t.me/setlanguage/ |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://td.telegram.org |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://td.telegram.org/ |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://tdesktop.com/ |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://tdesktop.com/crash.php?act=query_report&apiid=%1&version=%2&dmp=%3&platform=%4 |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://tdesktop.com/crash.php?act=report |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF65A60A000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/ |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/blog/monetization-for-channelsAd |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/blog/telegram-business#chatbots-for-businessbot |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/blog/telegram-starsUnlock |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/faq |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/faq#general-questionsTelegram |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/privacy |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/privacy-tpa |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/tos |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/tos/mini-appsNotification |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/tos/stars |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/tos/starsAll |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/tos/starsMedia |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/tos/starsSubscription |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65B91B000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telegram.org/tos/starsWithdraw |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://telesco.pe/ |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://twitter.com/ |
Source: Telegram.exe, 0000000E.00000000.3311646704.00007FF65BA85000.00000008.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://twitter.com/hashtag/ |
Source: Telegram.exe, 0000000E.00000000.3308240792.00007FF659502000.00000002.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://webrtc.googlesource.com/src/ |
Source: 7za.exe, 0000000A.00000003.3292432282.0000000002F30000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: unknown |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" |
|
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2012,i,5296181332326272263,8081676399308569334,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
|
Source: unknown |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://investors.spotify.com.sg.misteri.us.kg/" |
|
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=4200 --field-trial-handle=2012,i,5296181332326272263,8081676399308569334,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
|
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=4308 --field-trial-handle=2012,i,5296181332326272263,8081676399308569334,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
|
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Windows\SysWOW64\unarchiver.exe "C:\Windows\SysWOW64\unarchiver.exe" "C:\Users\user\Downloads\tportable-x64.5.5.5.zip" |
|
Source: C:\Windows\SysWOW64\unarchiver.exe |
Process created: C:\Windows\SysWOW64\7za.exe "C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\34yqvajp.yju" "C:\Users\user\Downloads\tportable-x64.5.5.5.zip" |
|
Source: C:\Windows\SysWOW64\7za.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\unarchiver.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C "C:\Users\user\AppData\Local\Temp\34yqvajp.yju\Telegram\Telegram.exe" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\34yqvajp.yju\Telegram\Telegram.exe C:\Users\user\AppData\Local\Temp\34yqvajp.yju\Telegram\Telegram.exe |
|
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2012,i,5296181332326272263,8081676399308569334,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=4200 --field-trial-handle=2012,i,5296181332326272263,8081676399308569334,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=4308 --field-trial-handle=2012,i,5296181332326272263,8081676399308569334,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Windows\SysWOW64\unarchiver.exe "C:\Windows\SysWOW64\unarchiver.exe" "C:\Users\user\Downloads\tportable-x64.5.5.5.zip" |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\SysWOW64\unarchiver.exe |
Process created: C:\Windows\SysWOW64\7za.exe "C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\34yqvajp.yju" "C:\Users\user\Downloads\tportable-x64.5.5.5.zip" |
Jump to behavior |
Source: C:\Windows\SysWOW64\unarchiver.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C "C:\Users\user\AppData\Local\Temp\34yqvajp.yju\Telegram\Telegram.exe" |
Jump to behavior |