Windows Analysis Report
PInstaller.exe

Overview

General Information

Sample name: PInstaller.exe
Analysis ID: 1526549
MD5: ea17d9a8373df3180020a861f91333c0
SHA1: beee77b8e24c4dd91e13f8154d180cbab37fccf2
SHA256: f5813155f25b4d8b8e3aee7b5353467973e5907dd743075676c462cff9f4acfe
Tags: exeuser-JolefanM
Infos:

Detection

STRRAT
Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected STRRAT
AI detected suspicious sample
Connects to a pastebin service (likely for C&C)
Contains functionality for read data from the clipboard
Contains functionality to detect virtual machines (SLDT)
Contains functionality to shutdown / reboot the system
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
PE file contains sections with non-standard names
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

AV Detection

barindex
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: PInstaller.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\README.txt Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\THIRDPARTYLICENSEREADME-JAVAFX.txt Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\THIRDPARTYLICENSEREADME-JAVAFX.txt Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\THIRDPARTYLICENSEREADME.txt Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\THIRDPARTYLICENSEREADME.txt Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\msvcr100.dll Jump to behavior
Source: unknown HTTPS traffic detected: 104.20.3.235:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: PInstaller.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libt2k\t2k.pdb source: t2k.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libjava\java.pdb source: javaw.exe, 00000003.00000002.2002355616.000000006E233000.00000002.00000001.01000000.0000000A.sdmp, java.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libnio\nio.pdbic source: javaw.exe, 00000003.00000002.2000391361.000000006C037000.00000002.00000001.01000000.0000000D.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libjava\java.pdb'% source: javaw.exe, 00000003.00000002.2002355616.000000006E233000.00000002.00000001.01000000.0000000A.sdmp, java.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libmlib_image\mlib_image.pdb9 source: mlib_image.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libawt\awt.pdb source: javaw.exe, 00000003.00000002.1997227041.000000006B409000.00000002.00000001.01000000.00000013.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libnet\net.pdb source: javaw.exe, 00000003.00000002.2000685361.000000006C08D000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libbci\bci.pdb source: bci.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libverify\verify.pdb source: javaw.exe, 00000003.00000002.2002514380.000000006F986000.00000002.00000001.01000000.00000009.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libsunmscapi\sunmscapi.pdb source: javaw.exe, 00000003.00000002.1996049209.000000006ADD4000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\tnameserv_objs\tnameserv.pdb source: tnameserv.exe.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\javaw_objs\javaw.pdb source: javaw.exe, 00000003.00000002.1973447456.0000000000DDC000.00000002.00000001.01000000.00000006.sdmp, javaw.exe, 00000003.00000000.1897955244.0000000000DDC000.00000002.00000001.01000000.00000006.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\liblcms\lcms.pdb* source: lcms.dll.0.dr
Source: Binary string: C:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\hotspot\windows_i486_compiler1\product\jvm.pdb source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libawt\awt.pdb8^DkdwBk source: javaw.exe, 00000003.00000002.1997227041.000000006B409000.00000002.00000001.01000000.00000013.sdmp
Source: Binary string: msvcr100.i386.pdb source: javaw.exe, 00000003.00000002.2001972892.000000006C471000.00000020.00000001.01000000.00000007.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\liblcms\lcms.pdb source: lcms.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libnio\nio.pdb source: javaw.exe, 00000003.00000002.2000391361.000000006C037000.00000002.00000001.01000000.0000000D.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\orbd_objs\orbd.pdb source: orbd.exe.0.dr
Source: Binary string: msvcr120.i386.pdb source: javaw.exe, 00000003.00000002.1999710623.000000006BF41000.00000020.00000001.01000000.0000000E.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libzip\zip.pdb source: javaw.exe, 00000003.00000002.2002220765.000000006DB4A000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: msvcp120.i386.pdb source: javaw.exe, 00000003.00000002.1999224847.000000006BEC1000.00000020.00000001.01000000.0000000F.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libmlib_image\mlib_image.pdb source: mlib_image.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libsunec\sunec.pdb$ source: javaw.exe, 00000003.00000002.1996512018.000000006ADF3000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libjavaaccessbridge-32\JavaAccessBridge-32.pdb) source: JavaAccessBridge-32.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libsunec\sunec.pdb source: javaw.exe, 00000003.00000002.1996512018.000000006ADF3000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libjavaaccessbridge-32\JavaAccessBridge-32.pdb source: JavaAccessBridge-32.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libjawt\jawt.pdb source: jawt.dll.0.dr
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_00406A05 FindFirstFileW,FindClose, 0_2_00406A05
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_00402930 FindFirstFileW, 0_2_00402930
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_00405DB4 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, 0_2_00405DB4
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\Roaming\InstallerPDW\jre\lib\ Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\Roaming\InstallerPDW\jre\ Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\Roaming\InstallerPDW\ Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\Roaming\ Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\ Jump to behavior

Networking

barindex
Source: unknown DNS query: name: pastebin.com
Source: Joe Sandbox View IP Address: 104.20.3.235 104.20.3.235
Source: Joe Sandbox View IP Address: 104.20.3.235 104.20.3.235
Source: Joe Sandbox View ASN Name: CLOUDFLARENETUS CLOUDFLARENETUS
Source: Joe Sandbox View JA3 fingerprint: 2db6873021f2a95daa7de0d93a1d1bf2
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: pastebin.com
Source: javaw.exe, 00000003.00000002.1976371401.000000000566B000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: HTTP://WWW.CHAMBERSIGN.ORG
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/allow-java-encodings
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/allow-java-encodings:
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/continue-after-fatal-error
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/create-cdata-nodes
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/create-cdata-nodeshy
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/disallow-doctype-decl
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/dom/create-entity-ref-nodes
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/dom/defer-node-expansion
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/dom/defer-node-expansionG
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/dom/include-ignorable-whitespace
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/generate-synthetic-annotations
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/generate-synthetic-annotations3
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/honour-all-schemaLocations
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/honour-all-schemaLocations/
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/include-comments
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/internal/parser-settings
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/internal/tolerate-duplicates
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/internal/tolerate-duplicatesO
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/internal/validation/schema/use-grammar-pool-only
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/namespace-growth
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/namespacesY
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/nonvalidating/load-external-dtd
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/nonvalidating/load-external-dtdA
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/scanner/notify-builtin-refs
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/scanner/notify-char-refs
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/scanner/notify-char-refs:
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/standard-uri-conformant
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validate-annotations
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validate-annotations9
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/balance-syntax-trees
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/dynamic
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema-full-checking
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema-full-checking5
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema/augment-psvi
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema/augment-psvi=
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema/element-default
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema/element-default=
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema/normalized-value
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/schema:
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/warn-on-duplicate-attdef
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/warn-on-duplicate-attdef:
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/validation/warn-on-undeclared-elemdef
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/warn-on-duplicate-entitydef
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/xinclude
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/xinclude/fixup-base-uris
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/xinclude/fixup-base-uris6
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/xinclude/fixup-language
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/features/xincludeC
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/dom/current-element-node
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/dom/current-element-node7
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/dom/document-class-name
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/dom/document-class-name3
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/input-buffer-size
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/datatype-validator-factory
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/document-scanner
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/dtd-processor
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/dtd-processor7
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/dtd-scanner
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/dtd-scanner7
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/entity-manager
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/entity-manager:
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/entity-resolver
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/entity-resolver?
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/error-handler
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/error-handler=
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/error-reporter
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/error-reporter8
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/grammar-pool
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/namespace-binder
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/namespace-binderA
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/namespace-context
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/namespace-contextxQ
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/stax-entity-resolver
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/symbol-table
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/symbol-table6
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validation-manager
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validation-manager:
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validation/schema/dv-factory
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validation/schema/dv-factory8
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validator/dtd
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validator/dtdD
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validator/schema
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/validator/schema(
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/internal/xinclude-handler
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/locale
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/schema/external-noNamespaceSchemaLocation
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/schema/external-schemaLocation
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/schema/external-schemaLocationJ
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/properties/security-manager
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://apache.org/xml/xmlschema/1.0/anonymousTypes
Source: javaw.exe, 00000003.00000002.1985274707.000000000AAC7000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://asm.objectweb.org
Source: javaw.exe, 00000003.00000002.1985274707.000000000A813000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.2002355616.000000006E233000.00000002.00000001.01000000.0000000A.sdmp, java.dll.0.dr String found in binary or memory: http://bugreport.sun.com/bugreport/
Source: javaw.exe, 00000003.00000002.2002355616.000000006E233000.00000002.00000001.01000000.0000000A.sdmp, java.dll.0.dr String found in binary or memory: http://bugreport.sun.com/bugreport/java.vendor.url.bughttp://java.oracle.com/java.vendor.urljava.ven
Source: javaw.exe, 00000003.00000002.1985274707.000000000AFDE000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://cps.chambersign.org/cps/chambersroot.html
Source: javaw.exe, 00000003.00000002.1985274707.000000000AFDE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://cps.chambersign.org/cps/chambersroot.html0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B08A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.chambersign.org/chambersroot.crl
Source: javaw.exe, 00000003.00000002.1985274707.000000000AFDE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.chambersign.org/chambersroot.crl0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crlK
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl##
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/STCA.crl
Source: javaw.exe, 00000003.00000002.1985274707.000000000AFDE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/STCA.crl0
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.xrampsecurity.com/XGCA.crlCF
Source: javaw.exe, 00000003.00000002.2002355616.000000006E233000.00000002.00000001.01000000.0000000A.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000A818000.00000004.00001000.00020000.00000000.sdmp, java.dll.0.dr String found in binary or memory: http://java.oracle.com/
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/jaxp/xpath/dom
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/dom/properties/
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/dom/properties/ancestor-check
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/jaxp/properties/
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/jaxp/properties/schemaLanguage
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/jaxp/properties/schemaSource
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/jaxp/properties/schemaSource;
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/schema/features/
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/schema/features/)
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/schema/features/report-ignored-element-content-whitespace
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/schema/features/report-ignored-element-content-whitespace3
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/stream/properties/
Source: javaw.exe, 00000003.00000002.1985274707.000000000AE6A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/stream/properties/ignore-external-dtd
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/stream/properties/ignore-external-dtdR
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/stream/properties/reader-in-defined-state
Source: javaw.exe, 00000003.00000002.1985274707.000000000AE6A000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://java.sun.com/xml/stream/properties/report-cdata-event
Source: fxplugins.dll.0.dr String found in binary or memory: http://javafx.com/
Source: javaw.exe, 00000003.00000002.1985274707.000000000AD80000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://javafx.com/fxml/1
Source: javaw.exe, 00000003.00000002.1985274707.000000000AD80000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://javafx.com/javafx/8
Source: fxplugins.dll.0.dr String found in binary or memory: http://javafx.com/vp6decoderflvdemux
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.XMLConstants/feature/secure-processing
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/accessExternalDTD
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/accessExternalDTDR
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/accessExternalSchema
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/accessExternalSchemaHJs
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/accessExternalStylesheet
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.XMLConstants/property/accessExternalStylesheet8
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.dom.DOMResult/feature
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.dom.DOMSource/feature
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.sax.SAXResult/feature#
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.sax.SAXSource/feature
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, jfr.jar.0.dr String found in binary or memory: http://javax.xml.transform.sax.SAXTransformerFactory/feature
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.sax.SAXTransformerFactory/feature/xmlfilter
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.sax.SAXTransformerFactory/feature/xmlfilterss
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.sax.SAXTransformerFactory/featureH
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.stax.StAXResult/feature
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.stax.StAXSource/feature
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.stax.StAXSource/feature#
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.stream.StreamResult/feature
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.stream.StreamResult/feature-
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.stream.StreamSource/feature
Source: javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://javax.xml.transform.stream.StreamSource/feature6
Source: PInstaller.exe String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: javaw.exe, javaw.exe, 00000003.00000003.1957496475.000000001703B000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1991773621.0000000017032000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000003.1951924804.000000001701B000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://null.sun.com/
Source: PInstaller.exe, 00000000.00000002.1981099438.0000000000788000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://ocsp.example.net:80
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://ocsp.thawte.com0
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp String found in binary or memory: http://openjdk.java.net/jeps/220).
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://policy.camerfirma.com
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://policy.camerfirma.com0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://policy.camerfirma.coms
Source: javaw.exe, 00000003.00000002.1985274707.000000000AFDE000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://repository.swisssign.com/
Source: javaw.exe, 00000003.00000002.1985274707.000000000AFDE000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://repository.swisssign.com/0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://repository.swisssign.com/3
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://repository.swisssign.com/sq
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://s2.symcb.com0
Source: javaw.exe, 00000003.00000002.1985274707.000000000AFDE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://site.com/
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://sv.symcb.com/sv.crl0f
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://sv.symcb.com/sv.crt0
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://sv.symcd.com0&
Source: javaw.exe, 00000003.00000002.1976371401.0000000005319000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://trustcenter-crl.certificat2.com/Keynectis/KEYNECTIS_ROOT_CA.crl
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://trustcenter-crl.certificat2.com/Keynectis/KEYNECTIS_ROOT_CA.crl0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://trustcenter-crl.certificat2.com/Keynectis/KEYNECTIS_ROOT_CA.crlCk
Source: javaw.exe, 00000003.00000002.1976371401.0000000005319000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://trustcenter-crl.certificat2.com/Keynectis/KEYNECTIS_ROOT_CA.crlK
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.certplus.com/CRL/class2.crl
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.certplus.com/CRL/class2.crl0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.certplus.com/CRL/class3P.crl
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.certplus.com/CRL/class3P.crl0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.certplus.com/CRL/class3P.crlc
Source: javaw.exe, 00000003.00000002.1976371401.000000000566B000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.chambersign.org
Source: javaw.exe, 00000003.00000002.1985274707.000000000AFDE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.chambersign.org1
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/feature/use-service-mechanism
Source: jfr.jar.0.dr String found in binary or memory: http://www.oracle.com/hotspot/jdk/
Source: jfr.jar.0.dr String found in binary or memory: http://www.oracle.com/hotspot/jfr-info/
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp, jfr.jar.0.dr String found in binary or memory: http://www.oracle.com/hotspot/jvm/
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.oracle.com/hotspot/jvm/java/monitor/address
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.oracle.com/hotspot/jvm/vm/code_sweeper/id
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.oracle.com/hotspot/jvm/vm/compiler/id
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.oracle.com/hotspot/jvm/vm/gc/id
Source: javaw.exe, 00000003.00000002.1985274707.000000000AFDE000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1991531187.0000000016EC6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/technetwork/java/javafx/index.html
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.oracle.com/technetwork/java/javaseproducts/
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp String found in binary or memory: http://www.oracle.com/technetwork/java/javaseproducts/C:
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/is-standalone
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/elementAttributeLimit
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/enableExtensionFunctions
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/entityExpansionLimit
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/entityReplacementLimit
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/getEntityCountInfo
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/getEntityCountInfo%
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/maxElementDepth
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/maxGeneralEntitySizeLimit
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/maxOccurLimit
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/maxParameterEntitySizeLimit
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/maxXMLNameLimit
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/totalEntitySizeLimit
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/xmlSecurityPropertyManager
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.oracle.com/xml/jaxp/properties/xmlSecurityPropertyManager;
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.quovadis.bm
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.quovadis.bm0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.quovadis.bm;
Source: javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B08A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.quovadisglobal.com/cps
Source: javaw.exe, 00000003.00000002.1985274707.000000000AFDE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.quovadisglobal.com/cps0
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://www.symauth.com/cps0(
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: http://www.symauth.com/rpa00
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://xml.apache.org/xalan
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989115644.0000000015863000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.apache.org/xpath/features/whitespace-pre-stripping
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://xml.apache.org/xslt
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/allow-dtd-events-after-endDTD
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/allow-dtd-events-after-endDTDN
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/external-general-entities
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/external-general-entities7
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/external-parameter-entities
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/external-parameter-entities8
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/namespace-prefixes
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/namespaces
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000AE6A000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/string-interning
Source: javaw.exe, 00000003.00000003.1957826795.0000000015E55000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/string-interningfeature
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/use-entity-resolver2
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/validation
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/features/validations
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/properties/
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/properties/lexical-handler
Source: javaw.exe, 00000003.00000002.1989115644.0000000015725000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/properties/lexical-handler.
Source: javaw.exe, 00000003.00000002.1985274707.000000000ABEB000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/properties/xml-string
Source: javaw.exe, 00000003.00000002.1989866648.0000000015DD0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xml.org/sax/properties/xml-string?
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: https://d.symcb.com/cps0%
Source: fxplugins.dll.0.dr, javafx_iio.dll.0.dr, java.dll.0.dr, t2k.dll.0.dr, bci.dll.0.dr, lcms.dll.0.dr, tnameserv.exe.0.dr, JavaAccessBridge-32.dll.0.dr, jfxmedia.dll.0.dr, jawt.dll.0.dr, orbd.exe.0.dr, mlib_image.dll.0.dr String found in binary or memory: https://d.symcb.com/rpa0
Source: javaw.exe, 00000003.00000003.1951264881.00000000170AA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://gist.github.com/maxd/63691840fc372f22f470.
Source: javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1991531187.0000000016EC6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/TsSaltan/DevelNext-jURL/releases/latest
Source: javaw.exe, 00000003.00000002.1985274707.000000000A8CA000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/google/gson
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp, javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://ocsp.quovadisoffshore.com
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://ocsp.quovadisoffshore.com0
Source: javaw.exe, 00000003.00000002.1985274707.000000000B1D6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://ocsp.quovadisoffshore.comK
Source: javaw.exe, 00000003.00000002.1985274707.000000000B0A5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://pastebin.com/raw/WhdMR234
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown HTTPS traffic detected: 104.20.3.235:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_0040586C GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard, 0_2_0040586C
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_0040366B EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrlenW,wsprintfW,GetFileAttributesW,DeleteFileW,SetCurrentDirectoryW,CopyFileW,ExitProcess,CoUninitialize,ExitProcess,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,InitOnceBeginInitialize,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_0040366B
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Code function: 2_2_00405D30 2_2_00405D30
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Code function: 2_2_004013B0 2_2_004013B0
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Code function: String function: 00406E10 appears 37 times
Source: PInstaller.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: mal56.troj.winEXE@5/219@1/1
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Code function: 2_2_00401ED0 GetLastError,puts,ShellExecuteA,printf,fclose,MessageBoxA,FormatMessageA,strlen,strcat,LocalFree,fprintf,fprintf,fprintf, 2_2_00401ED0
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_0040366B EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrlenW,wsprintfW,GetFileAttributesW,DeleteFileW,SetCurrentDirectoryW,CopyFileW,ExitProcess,CoUninitialize,ExitProcess,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,InitOnceBeginInitialize,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_0040366B
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_00404B18 GetDlgItem,SetWindowTextW,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW, 0_2_00404B18
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_004021CF CoCreateInstance, 0_2_004021CF
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Code function: 2_2_00404740 FindResourceExA,LoadResource,LockResource,fprintf,FindResourceExA,LoadResource,LockResource,fprintf,strchr,strlen,strcpy,FindResourceExA,LoadResource,LockResource,fprintf,strchr,strlen,strcpy,strncpy,strlen,strcat,strncpy,strlen,strcat,FindResourceExA,LoadResource,LockResource,atoi,SetLastError,SetLastError,SetLastError,strcpy,fprintf,FindResourceExA,LoadResource,LockResource,atoi,strcpy,fprintf,fprintf,SetLastError,SetLastError,fprintf, 2_2_00404740
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Mutant created: NULL
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Local\Temp\nssDA44.tmp Jump to behavior
Source: PInstaller.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\PInstaller.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe File read: C:\Users\user\Desktop\PInstaller.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\PInstaller.exe "C:\Users\user\Desktop\PInstaller.exe"
Source: C:\Users\user\Desktop\PInstaller.exe Process created: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe C:\Users\user\AppData\Roaming\InstallerPDW\install.exe
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Process created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe "C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe" -Dfile.encoding=UTF-8 -classpath "jre\.;jre\..;jre\asm-all.jar;jre\bin;jre\COPYRIGHT;jre\dn-compiled-module.jar;jre\dn-php-sdk.jar;jre\gson.jar;jre\jphp-app-framework.jar;jre\jphp-core.jar;jre\jphp-desktop-ext.jar;jre\jphp-gui-ext.jar;jre\jphp-json-ext.jar;jre\jphp-runtime.jar;jre\jphp-xml-ext.jar;jre\jphp-zend-ext.jar;jre\jphp-zip-ext.jar;jre\lib;jre\LICENSE;jre\README.txt;jre\release;jre\slf4j-api.jar;jre\slf4j-simple.jar;jre\THIRDPARTYLICENSEREADME-JAVAFX.txt;jre\THIRDPARTYLICENSEREADME.txt;jre\Welcome.html;jre\zt-zip.jar" org.develnext.jphp.ext.javafx.FXLauncher
Source: C:\Users\user\Desktop\PInstaller.exe Process created: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Process created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe "C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe" -Dfile.encoding=UTF-8 -classpath "jre\.;jre\..;jre\asm-all.jar;jre\bin;jre\COPYRIGHT;jre\dn-compiled-module.jar;jre\dn-php-sdk.jar;jre\gson.jar;jre\jphp-app-framework.jar;jre\jphp-core.jar;jre\jphp-desktop-ext.jar;jre\jphp-gui-ext.jar;jre\jphp-json-ext.jar;jre\jphp-runtime.jar;jre\jphp-xml-ext.jar;jre\jphp-zend-ext.jar;jre\jphp-zip-ext.jar;jre\lib;jre\LICENSE;jre\README.txt;jre\release;jre\slf4j-api.jar;jre\slf4j-simple.jar;jre\THIRDPARTYLICENSEREADME-JAVAFX.txt;jre\THIRDPARTYLICENSEREADME.txt;jre\Welcome.html;jre\zt-zip.jar" org.develnext.jphp.ext.javafx.FXLauncher Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: wsock32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: d3d9.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32 Jump to behavior
Source: PInstaller.exe Static file information: File size 58639106 > 1048576
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\msvcr100.dll Jump to behavior
Source: PInstaller.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libt2k\t2k.pdb source: t2k.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libjava\java.pdb source: javaw.exe, 00000003.00000002.2002355616.000000006E233000.00000002.00000001.01000000.0000000A.sdmp, java.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libnio\nio.pdbic source: javaw.exe, 00000003.00000002.2000391361.000000006C037000.00000002.00000001.01000000.0000000D.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libjava\java.pdb'% source: javaw.exe, 00000003.00000002.2002355616.000000006E233000.00000002.00000001.01000000.0000000A.sdmp, java.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libmlib_image\mlib_image.pdb9 source: mlib_image.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libawt\awt.pdb source: javaw.exe, 00000003.00000002.1997227041.000000006B409000.00000002.00000001.01000000.00000013.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libnet\net.pdb source: javaw.exe, 00000003.00000002.2000685361.000000006C08D000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libbci\bci.pdb source: bci.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libverify\verify.pdb source: javaw.exe, 00000003.00000002.2002514380.000000006F986000.00000002.00000001.01000000.00000009.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libsunmscapi\sunmscapi.pdb source: javaw.exe, 00000003.00000002.1996049209.000000006ADD4000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\tnameserv_objs\tnameserv.pdb source: tnameserv.exe.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\javaw_objs\javaw.pdb source: javaw.exe, 00000003.00000002.1973447456.0000000000DDC000.00000002.00000001.01000000.00000006.sdmp, javaw.exe, 00000003.00000000.1897955244.0000000000DDC000.00000002.00000001.01000000.00000006.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\liblcms\lcms.pdb* source: lcms.dll.0.dr
Source: Binary string: C:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\hotspot\windows_i486_compiler1\product\jvm.pdb source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libawt\awt.pdb8^DkdwBk source: javaw.exe, 00000003.00000002.1997227041.000000006B409000.00000002.00000001.01000000.00000013.sdmp
Source: Binary string: msvcr100.i386.pdb source: javaw.exe, 00000003.00000002.2001972892.000000006C471000.00000020.00000001.01000000.00000007.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\liblcms\lcms.pdb source: lcms.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libnio\nio.pdb source: javaw.exe, 00000003.00000002.2000391361.000000006C037000.00000002.00000001.01000000.0000000D.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\orbd_objs\orbd.pdb source: orbd.exe.0.dr
Source: Binary string: msvcr120.i386.pdb source: javaw.exe, 00000003.00000002.1999710623.000000006BF41000.00000020.00000001.01000000.0000000E.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libzip\zip.pdb source: javaw.exe, 00000003.00000002.2002220765.000000006DB4A000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: msvcp120.i386.pdb source: javaw.exe, 00000003.00000002.1999224847.000000006BEC1000.00000020.00000001.01000000.0000000F.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libmlib_image\mlib_image.pdb source: mlib_image.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libsunec\sunec.pdb$ source: javaw.exe, 00000003.00000002.1996512018.000000006ADF3000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libjavaaccessbridge-32\JavaAccessBridge-32.pdb) source: JavaAccessBridge-32.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libsunec\sunec.pdb source: javaw.exe, 00000003.00000002.1996512018.000000006ADF3000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libjavaaccessbridge-32\JavaAccessBridge-32.pdb source: JavaAccessBridge-32.dll.0.dr
Source: Binary string: c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\build\windows-i586\jdk\objs\libjawt\jawt.pdb source: jawt.dll.0.dr
Source: jfxwebkit.dll.0.dr Static PE information: section name: .unwante
Source: prism_sw.dll.0.dr Static PE information: section name: _RDATA
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Code function: 3_3_170250D7 push cs; ret 3_3_17025176
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Code function: 3_3_16FCCC30 push eax; retf 3_3_16FCCC51
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Code function: 3_3_16FABDA6 push eax; ret 3_3_16FABDA9
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Code function: 3_3_16FADA9A push eax; ret 3_3_16FADA9D
Source: msvcr100.dll.0.dr Static PE information: section name: .text entropy: 6.90903234258047
Source: msvcr100.dll0.0.dr Static PE information: section name: .text entropy: 6.90903234258047
Source: msvcr120.dll.0.dr Static PE information: section name: .text entropy: 6.95576372950548
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\prism_d3d.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\kinit.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\tnameserv.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\rmid.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\WindowsAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\dtplugin\npdeployJava1.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\msvcr100.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\j2pcsc.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\deploy.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\ssvagent.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\glass.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\prism_common.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\dcpr.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\pack200.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\decora_sse.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jsound.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javafx_font.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\gstreamer-lite.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\java.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jp2iexp.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\dt_shmem.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\klist.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\fxplugins.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\fontmanager.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jfr.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\msvcp120.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\msvcr120.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\management.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\orbd.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javacpl.cpl Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jdwp.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\java_crw_demo.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\rmiregistry.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jabswitch.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jsoundds.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\servertool.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javafx_iio.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\npt.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\WindowsAccessBridge.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\w2k_lsa_auth.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\j2pkcs11.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jjs.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\verify.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\JAWTAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\unpack.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\bci.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\instrument.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\mlib_image.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\ssv.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\glib-lite.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\policytool.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\kcms.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\lcms.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\JavaAccessBridge.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\t2k.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\sunec.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jfxmedia.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jli.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\wsdetect.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jfxwebkit.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\resource.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\java-rmi.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jpeg.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javacpl.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\nio.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javafx_font_t2k.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\net.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\splashscreen.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\unpack200.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\zip.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jp2launcher.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\awt.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\JavaAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jawt.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jp2ssv.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jaas_nt.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\JAWTAccessBridge.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\ktab.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\sunmscapi.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\dtplugin\deployJava1.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\prism_sw.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaws.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\eula.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\client\jvm.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\java.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\hprof.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jp2native.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\dt_socket.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jsdt.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\keytool.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\plugin2\msvcr100.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\plugin2\npjp2.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javacpl.cpl Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\README.txt Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\THIRDPARTYLICENSEREADME-JAVAFX.txt Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\THIRDPARTYLICENSEREADME-JAVAFX.txt Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\THIRDPARTYLICENSEREADME.txt Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe File created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\THIRDPARTYLICENSEREADME.txt Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Code function: 3_3_17023E4C sldt word ptr [eax] 3_3_17023E4C
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\prism_d3d.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\tnameserv.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\kinit.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\rmid.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\WindowsAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\dtplugin\npdeployJava1.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\msvcr100.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\j2pcsc.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\deploy.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\ssvagent.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\glass.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\prism_common.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\dcpr.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\pack200.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jsound.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\decora_sse.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javafx_font.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\gstreamer-lite.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\java.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jp2iexp.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\klist.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\dt_shmem.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\fxplugins.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\fontmanager.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\msvcp120.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\msvcr120.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jfr.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\management.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\orbd.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javacpl.cpl Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jdwp.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\java_crw_demo.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\rmiregistry.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jabswitch.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jsoundds.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\servertool.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javafx_iio.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\npt.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\WindowsAccessBridge.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\w2k_lsa_auth.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\j2pkcs11.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jjs.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\verify.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\JAWTAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\unpack.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\mlib_image.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\bci.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\ssv.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\instrument.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\glib-lite.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\policytool.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\kcms.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\lcms.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\JavaAccessBridge.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\t2k.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\sunec.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jfxmedia.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jli.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\wsdetect.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\resource.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jfxwebkit.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jpeg.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\java-rmi.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javacpl.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\nio.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javafx_font_t2k.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\splashscreen.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\net.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\unpack200.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jp2launcher.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\zip.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\awt.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\JavaAccessBridge-32.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jp2ssv.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jawt.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jaas_nt.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\JAWTAccessBridge.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\ktab.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\sunmscapi.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\prism_sw.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\dtplugin\deployJava1.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaws.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\eula.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\client\jvm.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\java.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\hprof.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jp2native.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\dt_socket.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\jsdt.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\keytool.exe Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\plugin2\npjp2.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\plugin2\msvcr100.dll Jump to dropped file
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_00406A05 FindFirstFileW,FindClose, 0_2_00406A05
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_00402930 FindFirstFileW, 0_2_00402930
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_00405DB4 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, 0_2_00405DB4
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\Roaming\InstallerPDW\jre\lib\ Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\Roaming\InstallerPDW\jre\ Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\Roaming\InstallerPDW\ Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\AppData\Roaming\ Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe File opened: C:\Users\user\ Jump to behavior
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: l{constant pool}code cache C-heap hand metaspace chunks dict zone strs syms heap threads [Verifying Genesis-2147483648Unable to link/verify Finalizer.register methodUnable to link/verify ClassLoader.addClass methodProtectionDomain.impliesCreateAccessControlContext() has the wrong linkageUnable to link/verify Unsafe.throwIllegalAccessError methodJava heap space: failed reallocation of scalar replaced objectsGC overhead limit exceededRequested array size exceeds VM limitCompressed class spaceJava heap spaceUnable to link/verify VirtualMachineError classC:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\hotspot\src\share\vm\oops\arrayKlass.cpp[]guarantee(component_mirror()->klass() != NULL) failedshould have a classC:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\hotspot\src\share\vm\gc_interface/collectedHeap.inline.hpp - length: %dguarantee(a->length() >= 0) failedarray with negative length?guarantee(obj->is_array()) failedmust be arrayshould be klassguarantee(is_constantPool()) failedvtable restored by this call<pseudo-string> cache=0x%08x (extra) for /operands[%d]/preresolutionconstant pool [%d]A constant pool lockC:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u101\7261\hotspot\src\share\vm\oops\constantPool.cppguarantee(!ConstantPool::is_invokedynamic_index(which)) failedan invokedynamic instruction does not have a klassRESOLVE %s %s
Source: javaw.exe, 00000003.00000003.1898754307.00000000156CC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: com/sun/corba/se/impl/util/SUNVMCID.classPK
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp, classlist.0.dr Binary or memory string: java/lang/VirtualMachineError
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: Unable to link/verify VirtualMachineError class
Source: javaw.exe, 00000003.00000002.1974453691.000000000151B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll3
Source: javaw.exe, 00000003.00000003.1898754307.00000000156CC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: org/omg/CORBA/OMGVMCID.classPK
Source: javaw.exe, 00000003.00000002.1975550538.0000000003030000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: cjava/lang/VirtualMachineError
Source: javaw.exe, 00000003.00000002.1975550538.0000000003030000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: t[Ljava/lang/VirtualMachineError;
Source: javaw.exe, 00000003.00000003.1898754307.00000000156CC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: )Q+com/sun/corba/se/impl/util/SUNVMCID.classPK
Source: javaw.exe, 00000003.00000002.2001338707.000000006C361000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: _well_known_klasses[SystemDictionary::VirtualMachineError_klass_knum]
Source: javaw.exe, 00000003.00000003.1898754307.00000000156CC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: java/lang/VirtualMachineError.classPK
Source: javaw.exe, 00000003.00000002.1975550538.0000000003030000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: lVirtualMachineError.java
Source: C:\Users\user\Desktop\PInstaller.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Code function: 2_2_00401150 SetUnhandledExceptionFilter,__getmainargs,_iob,_iob,_setmode,_iob,_iob,_setmode,__p__fmode,__p__environ,_cexit,ExitProcess, 2_2_00401150
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Memory protected: page read and write | page guard Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Process created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe "C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe" -Dfile.encoding=UTF-8 -classpath "jre\.;jre\..;jre\asm-all.jar;jre\bin;jre\COPYRIGHT;jre\dn-compiled-module.jar;jre\dn-php-sdk.jar;jre\gson.jar;jre\jphp-app-framework.jar;jre\jphp-core.jar;jre\jphp-desktop-ext.jar;jre\jphp-gui-ext.jar;jre\jphp-json-ext.jar;jre\jphp-runtime.jar;jre\jphp-xml-ext.jar;jre\jphp-zend-ext.jar;jre\jphp-zip-ext.jar;jre\lib;jre\LICENSE;jre\README.txt;jre\release;jre\slf4j-api.jar;jre\slf4j-simple.jar;jre\THIRDPARTYLICENSEREADME-JAVAFX.txt;jre\THIRDPARTYLICENSEREADME.txt;jre\Welcome.html;jre\zt-zip.jar" org.develnext.jphp.ext.javafx.FXLauncher Jump to behavior
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Process created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe "c:\users\user\appdata\roaming\installerpdw\jre\bin\javaw.exe" -dfile.encoding=utf-8 -classpath "jre\.;jre\..;jre\asm-all.jar;jre\bin;jre\copyright;jre\dn-compiled-module.jar;jre\dn-php-sdk.jar;jre\gson.jar;jre\jphp-app-framework.jar;jre\jphp-core.jar;jre\jphp-desktop-ext.jar;jre\jphp-gui-ext.jar;jre\jphp-json-ext.jar;jre\jphp-runtime.jar;jre\jphp-xml-ext.jar;jre\jphp-zend-ext.jar;jre\jphp-zip-ext.jar;jre\lib;jre\license;jre\readme.txt;jre\release;jre\slf4j-api.jar;jre\slf4j-simple.jar;jre\thirdpartylicensereadme-javafx.txt;jre\thirdpartylicensereadme.txt;jre\welcome.html;jre\zt-zip.jar" org.develnext.jphp.ext.javafx.fxlauncher
Source: C:\Users\user\AppData\Roaming\InstallerPDW\install.exe Process created: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe "c:\users\user\appdata\roaming\installerpdw\jre\bin\javaw.exe" -dfile.encoding=utf-8 -classpath "jre\.;jre\..;jre\asm-all.jar;jre\bin;jre\copyright;jre\dn-compiled-module.jar;jre\dn-php-sdk.jar;jre\gson.jar;jre\jphp-app-framework.jar;jre\jphp-core.jar;jre\jphp-desktop-ext.jar;jre\jphp-gui-ext.jar;jre\jphp-json-ext.jar;jre\jphp-runtime.jar;jre\jphp-xml-ext.jar;jre\jphp-zend-ext.jar;jre\jphp-zip-ext.jar;jre\lib;jre\license;jre\readme.txt;jre\release;jre\slf4j-api.jar;jre\slf4j-simple.jar;jre\thirdpartylicensereadme-javafx.txt;jre\thirdpartylicensereadme.txt;jre\welcome.html;jre\zt-zip.jar" org.develnext.jphp.ext.javafx.fxlauncher Jump to behavior
Source: C:\Users\user\Desktop\PInstaller.exe Code function: 0_2_0040366B EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrlenW,wsprintfW,GetFileAttributesW,DeleteFileW,SetCurrentDirectoryW,CopyFileW,ExitProcess,CoUninitialize,ExitProcess,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,InitOnceBeginInitialize,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_0040366B
Source: C:\Users\user\AppData\Roaming\InstallerPDW\jre\bin\javaw.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: Process Memory Space: javaw.exe PID: 1816, type: MEMORYSTR

Remote Access Functionality

barindex
Source: Yara match File source: Process Memory Space: javaw.exe PID: 1816, type: MEMORYSTR
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs