Source: | Binary string: C:\Windows\mscorlib.pdbpdblib.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007B6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: HPko8C:\Windows\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: C:\Windows\InstallUtil.pdbpdbtil.pdb}| source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\exe\InstallUtil.pdb` source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\mscorlib.pdb0% source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: @wo.pdb source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: Ywhazhugqk.exe, 00000001.00000002.1622422495.0000000003D17000.00000004.00000800.00020000.00000000.sdmp, Ywhazhugqk.exe, 00000001.00000002.1627988516.0000000006360000.00000004.08000000.00040000.00000000.sdmp, Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: Ywhazhugqk.exe, 00000001.00000002.1622422495.0000000003D17000.00000004.00000800.00020000.00000000.sdmp, Ywhazhugqk.exe, 00000001.00000002.1627988516.0000000006360000.00000004.08000000.00040000.00000000.sdmp, Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdbSHA256}Lq source: Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007B6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdb source: Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdb0 source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007B6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\System.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\System.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ?woC:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: InstallUtil.pdbllUtil.pdbpdbtil.pdb.30319\InstallUtil.pdb` source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\exe\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007B6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InstallUtil.pdb.NETFrameworkv4.0.30319InstallUtil.exe source: InstallUtil.exe, 00000002.00000002.2851755776.0000000000855000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Ssymbols\exe\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\mscorlib.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ((.pdb s( source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\System.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-net |
Source: Ywhazhugqk.exe, 00000001.00000002.1622422495.0000000003C15000.00000004.00000800.00020000.00000000.sdmp, Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-netJ |
Source: Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp | String found in binary or memory: https://github.com/mgravell/protobuf-neti |
Source: Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/11564914/23354; |
Source: Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp, Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002BDC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/14436606/23354 |
Source: Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp | String found in binary or memory: https://stackoverflow.com/q/2152978/23354 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_0117D070 | 1_2_0117D070 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_01177AA8 | 1_2_01177AA8 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_0117BD50 | 1_2_0117BD50 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_01177A98 | 1_2_01177A98 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_058AA250 | 1_2_058AA250 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_058AAE00 | 1_2_058AAE00 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_058A4E00 | 1_2_058A4E00 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_058AB08D | 1_2_058AB08D |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_058AA240 | 1_2_058AA240 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_058AADF1 | 1_2_058AADF1 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_058A1EE0 | 1_2_058A1EE0 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_058A4E00 | 1_2_058A4E00 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_05F0EF48 | 1_2_05F0EF48 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_05EF0040 | 1_2_05EF0040 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_05EF001D | 1_2_05EF001D |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_065E26CF | 1_2_065E26CF |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_065E277F | 1_2_065E277F |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_065E23D8 | 1_2_065E23D8 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_065E23C8 | 1_2_065E23C8 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_065E27B6 | 1_2_065E27B6 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_065E2831 | 1_2_065E2831 |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_065E28BF | 1_2_065E28BF |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Code function: 1_2_065E28B4 | 1_2_065E28B4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_024973E8 | 2_2_024973E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_02492E68 | 2_2_02492E68 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_02494076 | 2_2_02494076 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_024971ED | 2_2_024971ED |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_02492E59 | 2_2_02492E59 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_02494660 | 2_2_02494660 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_02494670 | 2_2_02494670 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_02492E68 | 2_2_02492E68 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_02493F78 | 2_2_02493F78 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_04C41028 | 2_2_04C41028 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 2_2_04C41038 | 2_2_04C41038 |
Source: Ywhazhugqk.exe, 00000001.00000002.1622422495.0000000003C15000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs Ywhazhugqk.exe |
Source: Ywhazhugqk.exe, 00000001.00000002.1622422495.0000000003C15000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameGtozzbt.dll" vs Ywhazhugqk.exe |
Source: Ywhazhugqk.exe, 00000001.00000002.1622422495.0000000003D17000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs Ywhazhugqk.exe |
Source: Ywhazhugqk.exe, 00000001.00000002.1607876321.0000000000DBE000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs Ywhazhugqk.exe |
Source: Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs Ywhazhugqk.exe |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002CF7000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameBabeoie.exe" vs Ywhazhugqk.exe |
Source: Ywhazhugqk.exe, 00000001.00000002.1627988516.0000000006360000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs Ywhazhugqk.exe |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002B81000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename vs Ywhazhugqk.exe |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs Ywhazhugqk.exe |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002F11000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameBabeoie.exe" vs Ywhazhugqk.exe |
Source: 1.2.Ywhazhugqk.exe.6360000.7.raw.unpack, User.cs | Security API names: System.Security.Principal.SecurityIdentifier.Translate(System.Type) |
Source: 1.2.Ywhazhugqk.exe.6360000.7.raw.unpack, Task.cs | Security API names: Microsoft.Win32.TaskScheduler.Task.GetAccessControl(System.Security.AccessControl.AccessControlSections) |
Source: 1.2.Ywhazhugqk.exe.6360000.7.raw.unpack, TaskFolder.cs | Security API names: Microsoft.Win32.TaskScheduler.TaskFolder.GetAccessControl(System.Security.AccessControl.AccessControlSections) |
Source: 1.2.Ywhazhugqk.exe.6360000.7.raw.unpack, TaskSecurity.cs | Security API names: Microsoft.Win32.TaskScheduler.TaskSecurity.GetAccessControlSectionsFromChanges() |
Source: 1.2.Ywhazhugqk.exe.6360000.7.raw.unpack, TaskSecurity.cs | Security API names: System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(System.Security.AccessControl.AccessRule) |
Source: 1.2.Ywhazhugqk.exe.6360000.7.raw.unpack, TaskPrincipal.cs | Security API names: System.Security.Principal.WindowsIdentity.GetCurrent() |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: | Binary string: C:\Windows\mscorlib.pdbpdblib.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007B6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: HPko8C:\Windows\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: C:\Windows\InstallUtil.pdbpdbtil.pdb}| source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\exe\InstallUtil.pdb` source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\mscorlib.pdb0% source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: @wo.pdb source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: Ywhazhugqk.exe, 00000001.00000002.1622422495.0000000003D17000.00000004.00000800.00020000.00000000.sdmp, Ywhazhugqk.exe, 00000001.00000002.1627988516.0000000006360000.00000004.08000000.00040000.00000000.sdmp, Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: Ywhazhugqk.exe, 00000001.00000002.1622422495.0000000003D17000.00000004.00000800.00020000.00000000.sdmp, Ywhazhugqk.exe, 00000001.00000002.1627988516.0000000006360000.00000004.08000000.00040000.00000000.sdmp, Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdbSHA256}Lq source: Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007B6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: protobuf-net.pdb source: Ywhazhugqk.exe, 00000001.00000002.1627308912.0000000005850000.00000004.08000000.00040000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdb0 source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007B6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\System.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\System.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ?woC:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: InstallUtil.pdbllUtil.pdbpdbtil.pdb.30319\InstallUtil.pdb` source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\exe\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007B6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InstallUtil.pdb.NETFrameworkv4.0.30319InstallUtil.exe source: InstallUtil.exe, 00000002.00000002.2851755776.0000000000855000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.00000000007FB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Ssymbols\exe\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\mscorlib.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ((.pdb s( source: InstallUtil.exe, 00000002.00000002.2851220900.0000000000538000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\System.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\InstallUtil.pdb source: InstallUtil.exe, 00000002.00000002.2851755776.000000000081C000.00000004.00000020.00020000.00000000.sdmp |
Source: 1.2.Ywhazhugqk.exe.5850000.6.raw.unpack, TypeModel.cs | .Net Code: TryDeserializeList |
Source: 1.2.Ywhazhugqk.exe.5850000.6.raw.unpack, ListDecorator.cs | .Net Code: Read |
Source: 1.2.Ywhazhugqk.exe.5850000.6.raw.unpack, TypeSerializer.cs | .Net Code: CreateInstance |
Source: 1.2.Ywhazhugqk.exe.5850000.6.raw.unpack, TypeSerializer.cs | .Net Code: EmitCreateInstance |
Source: 1.2.Ywhazhugqk.exe.5850000.6.raw.unpack, TypeSerializer.cs | .Net Code: EmitCreateIfNull |
Source: 1.2.Ywhazhugqk.exe.6360000.7.raw.unpack, ReflectionHelper.cs | .Net Code: InvokeMethod |
Source: 1.2.Ywhazhugqk.exe.6360000.7.raw.unpack, ReflectionHelper.cs | .Net Code: InvokeMethod |
Source: 1.2.Ywhazhugqk.exe.6360000.7.raw.unpack, XmlSerializationHelper.cs | .Net Code: ReadObjectProperties |
Source: 1.2.Ywhazhugqk.exe.417e7b8.3.raw.unpack, NOdjZgRRgji8ly7hKU.cs | .Net Code: pCFvFxlih System.AppDomain.Load(byte[]) |
Source: 1.2.Ywhazhugqk.exe.417e7b8.3.raw.unpack, -Module--854d8771-8713-4a41-bf73-aa5bde6e6cb4-.cs | High entropy of concatenated method names: 'kc8d26309dde547208d3ae1a0f4a001b3', 'ReadPublisher', 'QueryPublisher', 'LoginPublisher', 'eMw8iFbmd25DJP2eoFF', 'S59J6bbrWR1IgxJve9y', 'GvCG9ibsZN6QYIW2scZ', 'poPCc2bPBy3WOGtGF2m', 'YufHKlb5rEGDyIIlNLR', 'qMHW9nbNVItF9x3Hg7x' |
Source: 1.2.Ywhazhugqk.exe.417e7b8.3.raw.unpack, dK820iKElZV9xe4S2ca.cs | High entropy of concatenated method names: 'a4pi4sl6O3', 'NlxjBVbkvgM1XG90paX', 'jU5XOBbSgGcFjcNJqhN', 'nqmYUQbM1D72G9M1coB', 'foBig0bG4KbNIIpG4jE', 'bwfBLQbAadpucgDea1V', 'WnQc6obhVFfMnBRPjMK', 'Pub0bUbZIh8QbihYSQe', 'KrlJUjbJc08fAIVgNh1', 'YgpJI8bT7tsMXgA8qgq' |
Source: 1.2.Ywhazhugqk.exe.417e7b8.3.raw.unpack, sx07G6LnvyoYlOppsgQ.cs | High entropy of concatenated method names: 'YVcLCovi4G', 'xD9LzKq9AB', 'eh3lY3vEgQ', 'URLl3WdHDc', 'EAKlKBxYm9', 'iNlld5ioBm', 'TcXlLW6L5f', 'qiollZ816s', 'HP5lch8Kuq', 'MPRlWvFrBi' |
Source: 1.2.Ywhazhugqk.exe.417e7b8.3.raw.unpack, tmH5Zoh2A6APmbnSTO.cs | High entropy of concatenated method names: 'vBJKshjdfF', 'byPKmJE9OV', 'NtNdTpQDBJgVqFSi7u3', 'tpuYXmQBZRldDxsUCm8', 'O2NVnAQ57cgvLZv6WDv', 'QJb4SYQmnwXk3HoEJGW', 'QF9SLgQPM02avZL3grC', 'RINKNYM1LC', 'Hp7EACQhhApAaEROkgs', 'iioFg9QZUrdCEx91oa8' |
Source: 1.2.Ywhazhugqk.exe.417e7b8.3.raw.unpack, h8U4IOPmfNh4mJwTud.cs | High entropy of concatenated method names: 'qXFNVHPny', 'KfkD4Wyyq', 'LLlButaok', 'piSwn7cGqfMoF6MTCHb', 'zXVdpwcAZJgC1XjnhwV', 'mJfYo2cJ0TdjcPW2FOs', 'C7QWxEcSsAcsYnG6wIa', 'OVV3cscMaJIZ6tGQaXO', 'eU3EwicTdYMJI5INDuH', 'xhChPmc6mOF2n4c6jOA' |
Source: 1.2.Ywhazhugqk.exe.417e7b8.3.raw.unpack, ARR8kpKFQaRUYsP3p3P.cs | High entropy of concatenated method names: 'BKvJhWbfOruLf2P6MQL', 'ATNfsRb8lvX386UXpPF', 'Q82LPfw1pq', 'b04DBMbw8uISnng22xN', 'RMOoc5bo4ZPNKE1lm4D', 'iJfuivbFoVkf3I1pJD3', 'oNXULVbOPwwXtXxQN5U', 'JXmkuvbuUQ0OMEIy0UE', 'BHFyVWb24aHtPQt4yn0', 'punpg7b4wuUSrwWFSwl' |
Source: 1.2.Ywhazhugqk.exe.417e7b8.3.raw.unpack, NOdjZgRRgji8ly7hKU.cs | High entropy of concatenated method names: 'pCFvFxlih', 'SZB9kqGf4', 'KIsXF3yZ0', 'Rn9pocxRq', 'naktcw3hM', 'Me2jkVL3w', 'vhVrZucgs', 'AbfsqHlMK', 'uZvyVwlxkqYMAbxgha2', 'MQDabbleLYi0TrImvOV' |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Ywhazhugqk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002CF7000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: crosoft|VMWare|Virtual |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002CF7000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: vmware |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002CF7000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: q 1:en-CH:Microsoft|VMWare|Virtual@ |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002CF7000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: q 1:en-CH:VMware|VIRTUAL|A M I|Xen |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002CF7000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Microsoft|VMWare|Virtual |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002CF7000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: vmware@ |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002BDC000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: explorerJSbieDll.dllKcuckoomon.dllLwin32_process.handle='{0}'MParentProcessIdNcmdOselect * from Win32_BIOS8Unexpected WMI query failurePversionQSerialNumberSVMware|VIRTUAL|A M I|XenTselect * from Win32_ComputerSystemUmanufacturerVmodelWMicrosoft|VMWare|VirtualXjohnYannaZxxxxxxxx |
Source: Ywhazhugqk.exe, 00000001.00000002.1611726069.0000000002CF7000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: VMware|VIRTUAL|A M I|Xen@ |