Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetMemberRefProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetHandler source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.dotnet.pdb source: powershell.exe, 0000000B.00000002.1476246463.00007FFAAC5C0000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumTypeRefs source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetParent source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.ApplyEditAndContinue source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: System.Collections.Generic.IEnumerator<dnlib.DotNet.Pdb.PdbScope>.Current source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineModuleRef source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetNameFromToken source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DeleteFieldMarshal source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumMembers source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.FindField source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DeleteClassLayout source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.IsValidToken source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.Merge source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.FindMemberRef source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetParamProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetParamProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.GetSaveSize source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.FindTypeRef source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.ResetEnum source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetMethodProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumProperties source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumMembersWithName source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetCustomAttributeValue source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumMethodImpls source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineCustomAttribute source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineEvent source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetCustomAttributeByName source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineMethod source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.TranslateSigWithScope source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineUserString source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetTypeSpecFromToken source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.Save source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetPermissionSetProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.CountEnum source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumMethodSemantics source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetNativeCallConvFromSig source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumMethods source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumFields source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetTypeRefProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: +dnlib.DotNet.Pdb.PdbWriter+<GetScopes>d__17K source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetSigFromToken source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumTypeSpecs source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.dotnet.pdb.dss source: powershell.exe, 0000000B.00000002.1476246463.00007FFAAC5C0000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.CloseEnum source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetModuleRefProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SaveToMemory source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.pdb source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineTypeRefByName source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetScopeProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.FindMember source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetPropertyProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumParams source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.MergeEnd source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetEventProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumCustomAttributes source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetFieldProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumModuleRefs source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: System.Collections.Generic.IEnumerator<dnlib.DotNet.Pdb.PdbScope>.get_Current source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetCustomAttributeProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetFieldProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineParam source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetClassLayout source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DeleteToken source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumPermissionSets source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumUnresolvedMethods source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineNestedType source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Managed source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: +dnlib.DotNet.Pdb.PdbWriter+<GetScopes>d__17 source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetRVA source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetModuleFromScope source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineMethodImpl source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefinePinvokeMap source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetClassLayout source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineSecurityAttributeSet source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineMemberRef source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetPermissionSetProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetTypeDefProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineProperty source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.FindTypeDefByName source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetModuleProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetFieldRVA source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumFieldsWithName source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumMemberRefs source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.ResolveTypeRef source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SaveToStream source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetMethodSemantics source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetTypeDefProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetNestedClassProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.FindMethod source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DeletePinvokeMap source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.GetTokenFromTypeSpec source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetMethodImplFlags source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetPinvokeMap source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumSignatures source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetPinvokeMap source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetFieldMarshal source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumUserStrings source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetRVA source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefinePermissionSet source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetMethodProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetPropertyProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.dotnet.pdb.managed source: powershell.exe, 0000000B.00000002.1476246463.00007FFAAC5C0000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetUserString source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetInterfaceImplProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetFieldMarshal source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineTypeDef source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumTypeDefs source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineImportMember source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumInterfaceImpls source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetMemberProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineImportType source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: System.Collections.Generic.IEnumerable<dnlib.DotNet.Pdb.PdbScope>.GetEnumerator source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.GetTokenFromSig source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumEvents source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.GetParamForMethodIndex source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.DefineField source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.IsGlobal source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataImport.EnumMethodsWithName source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetEventProps source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1468589957.0000027D75CA0000.00000004.08000000.00040000.00000000.sdmp |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D00520000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://firebasestorage.googleapis.com |
Source: AddInProcess32.exe, 0000000E.00000002.2553669358.0000000002BA8000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000E.00000002.2553669358.0000000002BB0000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000E.00000002.2553669358.0000000002AD1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com |
Source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000E.00000002.2549002759.0000000000402000.00000040.00000400.00020000.00000000.sdmp, AddInProcess32.exe, 0000000E.00000002.2553669358.0000000002AD1000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000E.00000002.2553669358.0000000002B96000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: AddInProcess32.exe, 0000000E.00000002.2553669358.0000000002BB0000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.comp |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D01ACA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1435738029.0000027D10072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: wscript.exe, 00000000.00000003.1517826151.000001D52D429000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1520130545.000001D52D429000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://paste.ee/ |
Source: wscript.exe, 00000000.00000003.1518428835.000001D52F330000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1517658450.000001D52D466000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1521404049.000001D52EE83000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1520130545.000001D52D44E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1517797280.000001D52D44D000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1517220439.000001D52EE7F000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1517618403.000001D52D455000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1517765900.000001D52D46C000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1521135156.000001D52EE40000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1520438484.000001D52D46D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://paste.ee/d/gvOd3 |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D00223000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D0170C000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://raw.githubusercontent.com |
Source: powershell.exe, 00000008.00000002.1489002671.000001FFE5CA1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1413532103.0000027D00001000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000E.00000002.2553669358.0000000002AD1000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000E.00000002.2553669358.0000000002B96000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D0175D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D00223000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 0000000B.00000002.1435738029.0000027D1101C000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000E.00000002.2549002759.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://account.dyn.com/ |
Source: powershell.exe, 00000008.00000002.1489002671.000001FFE5D01000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.1489002671.000001FFE5CE9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1413532103.0000027D00001000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://analytics.paste.ee |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://analytics.paste.ee; |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://cdnjs.cloudflare.com |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://cdnjs.cloudflare.com; |
Source: powershell.exe, 0000000B.00000002.1435738029.0000027D10072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 0000000B.00000002.1435738029.0000027D10072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 0000000B.00000002.1435738029.0000027D10072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D00520000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://firebasestorage.googleapis.com |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D00434000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://firebasestorage.googleapis.com/v0/b/crypts2024.appspot.com/o/xavierorigin07102024.txt?alt=me |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://fonts.googleapis.com |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://fonts.gstatic.com; |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D00223000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D0122A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://go.micro |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D01ACA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1435738029.0000027D10072000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D0175D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://oneget.org |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D0175D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://oneget.orgX |
Source: wscript.exe, 00000000.00000002.1520580547.000001D52D490000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1516837297.000001D52D490000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://paste.ee/d/gvOd3 |
Source: wscript.exe, 00000000.00000002.1520580547.000001D52D490000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1516837297.000001D52D490000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://paste.ee/d/gvOd3ee/dD |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C3000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1516964493.000001D52D4C3000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1520758800.000001D52D4C3000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://paste.ee/d/gvOd3t |
Source: wscript.exe, 00000000.00000002.1520580547.000001D52D490000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1516837297.000001D52D490000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://paste.ee/zD |
Source: wscript.exe, 00000000.00000002.1520580547.000001D52D490000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1516837297.000001D52D490000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://paste.ee:443/d/gvOd3 |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D01707000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://raw.githubusercont |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D01685000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1413532103.0000027D00223000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://raw.githubusercontent.com |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D00223000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://raw.githubusercontent.com/NoDetectOn/NoDetectOn/refs/heads/main/DetahNoth-V.txt |
Source: powershell.exe, 0000000B.00000002.1413532103.0000027D00223000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://raw.githubusercontent.com/NoDetectOn/NoDetectOn/refs/heads/main/DetahNoth-V.txtC7I; |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://secure.gravatar.com |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://themes.googleusercontent.com |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com; |
Source: wscript.exe, 00000000.00000003.1516670838.000001D52D4C9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.gstatic.com |