Source: |
Binary string: D:\Source Code\AntiHead\AntiHead\x64\Release\aobtoaddrrw.pdb source: XSLHv0kxy7.exe, 00000000.00000002.1715918741.0000000002F71000.00000004.00000800.00020000.00000000.sdmp, P00LCUE.exe, 00000001.00000000.1713302423.00007FF620378000.00000002.00000001.01000000.00000006.sdmp, P00LCUE.exe, 00000001.00000002.1837068376.00007FF620378000.00000002.00000001.01000000.00000006.sdmp, P00LCUE.exe.0.dr |
Source: |
Binary string: Microsoft.VisualBasic.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Xml.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: mscorlib.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.ni.pdbRSDS source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Management.ni.pdbRSDSJ< source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Management.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: mscorlib.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Management.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Core.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Configuration.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: mscorlib.ni.pdbRSDS7^3l source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Configuration.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Configuration.ni.pdbRSDScUN source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: D:\Source Code\AntiHead\AntiHead\x64\Release\aobtoaddrrw.pdb'' source: XSLHv0kxy7.exe, 00000000.00000002.1715918741.0000000002F71000.00000004.00000800.00020000.00000000.sdmp, P00LCUE.exe, 00000001.00000000.1713302423.00007FF620378000.00000002.00000001.01000000.00000006.sdmp, P00LCUE.exe, 00000001.00000002.1837068376.00007FF620378000.00000002.00000001.01000000.00000006.sdmp, P00LCUE.exe.0.dr |
Source: |
Binary string: System.Xml.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Core.ni.pdbRSDS source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Xml.ni.pdbRSDS# source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Core.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: Microsoft.VisualBasic.pdb source: WER5045.tmp.dmp.8.dr |
Source: BLACKSUPER X.exe, 00000003.00000002.1998540533.0000000002CD2000.00000004.00000800.00020000.00000000.sdmp, BLACKSUPER X.exe, 00000003.00000002.1998540533.0000000002CB6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com |
Source: XSLHv0kxy7.exe, 00000000.00000002.1715918741.0000000002F71000.00000004.00000800.00020000.00000000.sdmp, BLACKSUPER X.exe, 00000003.00000000.1713951503.0000000000952000.00000002.00000001.01000000.00000007.sdmp, BLACKSUPER X.exe, 00000003.00000002.1998540533.0000000002C38000.00000004.00000800.00020000.00000000.sdmp, BLACKSUPER X.exe.0.dr |
String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: BLACKSUPER X.exe, 00000003.00000002.1998540533.0000000002CB6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Amcache.hve.8.dr |
String found in binary or memory: http://upx.sf.net |
Source: P00LCUE.exe, P00LCUE.exe, 00000001.00000002.1836572125.00000203B8FEC000.00000004.00000020.00020000.00000000.sdmp, P00LCUE.exe, 00000001.00000002.1837112806.00007FF62037C000.00000004.00000001.01000000.00000006.sdmp |
String found in binary or memory: https://keyauth.win/api/1.2/ |
Source: P00LCUE.exe, 00000001.00000002.1837112806.00007FF62037C000.00000004.00000001.01000000.00000006.sdmp |
String found in binary or memory: https://keyauth.win/api/1.2/k |
Source: P00LCUE.exe, 00000001.00000002.1836572125.00000203B8FEC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://keyauth.win/api/1.2/y |
Source: BLACKSUPER X.exe.0.dr, ErDSEmjKOU.cs |
Base64 encoded string: 'WE1AmsCB2TWvNaF1KPhUwSHbKi3Z9SmiOYvXoEA26vDq3zuas768HnJdTGMt' |
Source: BLACKSUPER X.exe.0.dr, GUgccjJtjJ.cs |
Base64 encoded string: 'MgmiczaY3BkFwWAsYXke543AHRV8FT9fYUnqfFqPYtuYYQiCCMGys5HYnAKP', 'hFc50vYm8887299Fdxp2hn44dmsVG28LfBPiTEShEjVl407eVpQPe5xFZk8t', 'uMzoEzFe7CEn7byPxHI3nFqEqtfTe776giARKpwHhMJ2IfWgnjvVMAbW3lbU', 'qZAG5hC16c2eNFepVxabxEdUj57hVumr3O7W0i0PmVs4SdQMmjNfoeMS7XF4', 'xCIRlcMxX1lgBCvsBuv0ZmhzJfytmnlsPaD3pFfmXHfptnJPO7IX3mQjb52i', 'g0PZNoSneTGDhbk8J934ioFZ2OTBUUHfpqaDIopJL7n4U6vhSchRTNZkkbBY', 'KtDkKK7th3WX1bE8rLGIKIm216PToiUZKjFnc7OIvuwqBkldyCObPG4TatCk', 'o0PZpqp6GUzOwgFN5fRvFZxt8nUkjlVpwvKTY3rsWPMNVo4jeZgx2KWrtXnS', 'q3J9g8TKg86eB2Uoqj4FJAx9723VsXanLeZkwO6T1Lbrw46agDT0hrNmqaFy' |
Source: BLACKSUPER X.exe.0.dr, PY7JtnPMei.cs |
Base64 encoded string: 'HBNoFrOxkbuAdBpXCEZtxhHUabWlzT57T0CUHQEXdS6mSUmAw1wWYuWDWsX6' |
Source: BLACKSUPER X.exe.0.dr, n3KIdyQiO9.cs |
Base64 encoded string: 'rgSOwPY8xVfDT9ZrBCnqTPkJ7GsCHwhqivO1mpH9TuSZ39QxGYhp6PjrQC6f', 'If1K0jS9QK4WQf73BUZfHJrFSvOflBIS5OMSCfMGJvjnEBgDy24cV8OQEjrD', 'qpJl67ANVjsQssJODQpyQZOe8ykoNXyRMvmsbut3Xhy6LO3Yju8rUvwz9i11', 'hVSSuRpw4Vfi9ytiumdRo3v8RHZTMYa5YyLvqMziBWU6x2egUR87g12NTEra', 'XrYyqd6F6fK8GUVPBOqxIgHnDqZ6juGRR8dB8UaK8QJUVbrrV2gxtuhEYUCI', 'SHL7hejTQPRyD7AqB7zxDgMPIvBir7Rs16ziWChiHK6GD8aI13oinC00uK5p' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, ErDSEmjKOU.cs |
Base64 encoded string: 'WE1AmsCB2TWvNaF1KPhUwSHbKi3Z9SmiOYvXoEA26vDq3zuas768HnJdTGMt' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, GUgccjJtjJ.cs |
Base64 encoded string: 'MgmiczaY3BkFwWAsYXke543AHRV8FT9fYUnqfFqPYtuYYQiCCMGys5HYnAKP', 'hFc50vYm8887299Fdxp2hn44dmsVG28LfBPiTEShEjVl407eVpQPe5xFZk8t', 'uMzoEzFe7CEn7byPxHI3nFqEqtfTe776giARKpwHhMJ2IfWgnjvVMAbW3lbU', 'qZAG5hC16c2eNFepVxabxEdUj57hVumr3O7W0i0PmVs4SdQMmjNfoeMS7XF4', 'xCIRlcMxX1lgBCvsBuv0ZmhzJfytmnlsPaD3pFfmXHfptnJPO7IX3mQjb52i', 'g0PZNoSneTGDhbk8J934ioFZ2OTBUUHfpqaDIopJL7n4U6vhSchRTNZkkbBY', 'KtDkKK7th3WX1bE8rLGIKIm216PToiUZKjFnc7OIvuwqBkldyCObPG4TatCk', 'o0PZpqp6GUzOwgFN5fRvFZxt8nUkjlVpwvKTY3rsWPMNVo4jeZgx2KWrtXnS', 'q3J9g8TKg86eB2Uoqj4FJAx9723VsXanLeZkwO6T1Lbrw46agDT0hrNmqaFy' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, PY7JtnPMei.cs |
Base64 encoded string: 'HBNoFrOxkbuAdBpXCEZtxhHUabWlzT57T0CUHQEXdS6mSUmAw1wWYuWDWsX6' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, n3KIdyQiO9.cs |
Base64 encoded string: 'rgSOwPY8xVfDT9ZrBCnqTPkJ7GsCHwhqivO1mpH9TuSZ39QxGYhp6PjrQC6f', 'If1K0jS9QK4WQf73BUZfHJrFSvOflBIS5OMSCfMGJvjnEBgDy24cV8OQEjrD', 'qpJl67ANVjsQssJODQpyQZOe8ykoNXyRMvmsbut3Xhy6LO3Yju8rUvwz9i11', 'hVSSuRpw4Vfi9ytiumdRo3v8RHZTMYa5YyLvqMziBWU6x2egUR87g12NTEra', 'XrYyqd6F6fK8GUVPBOqxIgHnDqZ6juGRR8dB8UaK8QJUVbrrV2gxtuhEYUCI', 'SHL7hejTQPRyD7AqB7zxDgMPIvBir7Rs16ziWChiHK6GD8aI13oinC00uK5p' |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: msvcp140.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: vcruntime140_1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: vcruntime140.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: vcruntime140.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: vcruntime140_1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: vcruntime140.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\P00LCUE.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: |
Binary string: D:\Source Code\AntiHead\AntiHead\x64\Release\aobtoaddrrw.pdb source: XSLHv0kxy7.exe, 00000000.00000002.1715918741.0000000002F71000.00000004.00000800.00020000.00000000.sdmp, P00LCUE.exe, 00000001.00000000.1713302423.00007FF620378000.00000002.00000001.01000000.00000006.sdmp, P00LCUE.exe, 00000001.00000002.1837068376.00007FF620378000.00000002.00000001.01000000.00000006.sdmp, P00LCUE.exe.0.dr |
Source: |
Binary string: Microsoft.VisualBasic.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Xml.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: mscorlib.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.ni.pdbRSDS source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Management.ni.pdbRSDSJ< source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Management.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: mscorlib.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Management.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Core.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Configuration.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: mscorlib.ni.pdbRSDS7^3l source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Configuration.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Configuration.ni.pdbRSDScUN source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: D:\Source Code\AntiHead\AntiHead\x64\Release\aobtoaddrrw.pdb'' source: XSLHv0kxy7.exe, 00000000.00000002.1715918741.0000000002F71000.00000004.00000800.00020000.00000000.sdmp, P00LCUE.exe, 00000001.00000000.1713302423.00007FF620378000.00000002.00000001.01000000.00000006.sdmp, P00LCUE.exe, 00000001.00000002.1837068376.00007FF620378000.00000002.00000001.01000000.00000006.sdmp, P00LCUE.exe.0.dr |
Source: |
Binary string: System.Xml.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Core.ni.pdbRSDS source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Xml.ni.pdbRSDS# source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: System.Core.ni.pdb source: WER5045.tmp.dmp.8.dr |
Source: |
Binary string: Microsoft.VisualBasic.pdb source: WER5045.tmp.dmp.8.dr |
Source: BLACKSUPER X.exe.0.dr, GUgccjJtjJ.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{a0XWIyjkU8Lc5tDyCbTtWGsCj5NYirpaA1BuwDjUVy6LHfTQLZKpTsfLnJURN3t7aIqt.kMDuGc02ge8cpng7ZsmLHbLlNFJehosu6PueqNeFTpFroP3Ez6Qf31H7kcmf7i17tVoZ,a0XWIyjkU8Lc5tDyCbTtWGsCj5NYirpaA1BuwDjUVy6LHfTQLZKpTsfLnJURN3t7aIqt._5w5tbhXWOeI8QMmQjxaviweEbjZQI8FEX4fgA01PL4ALkA4Qlmt3ulbW66O3Cuog4ne0,a0XWIyjkU8Lc5tDyCbTtWGsCj5NYirpaA1BuwDjUVy6LHfTQLZKpTsfLnJURN3t7aIqt.T7pUBdp507p6EP0P1Z0pSQExwbTJKlftMvMh1cq2bI5uEY7eZLz3ShCTblaY8AVzlCjc,a0XWIyjkU8Lc5tDyCbTtWGsCj5NYirpaA1BuwDjUVy6LHfTQLZKpTsfLnJURN3t7aIqt.VsewsTRWPJw52kvXd5Rc6Pefmw9KaWkL5tneRgIvzGqvJNrXhT0lTEnfAidFyJrPZZPE,tpDAhG0zUl.gcBtaiO2Ox()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: BLACKSUPER X.exe.0.dr, GUgccjJtjJ.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Rp5lo6l6F7[2],tpDAhG0zUl.VpSQw46ypp(Convert.FromBase64String(Rp5lo6l6F7[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, GUgccjJtjJ.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{a0XWIyjkU8Lc5tDyCbTtWGsCj5NYirpaA1BuwDjUVy6LHfTQLZKpTsfLnJURN3t7aIqt.kMDuGc02ge8cpng7ZsmLHbLlNFJehosu6PueqNeFTpFroP3Ez6Qf31H7kcmf7i17tVoZ,a0XWIyjkU8Lc5tDyCbTtWGsCj5NYirpaA1BuwDjUVy6LHfTQLZKpTsfLnJURN3t7aIqt._5w5tbhXWOeI8QMmQjxaviweEbjZQI8FEX4fgA01PL4ALkA4Qlmt3ulbW66O3Cuog4ne0,a0XWIyjkU8Lc5tDyCbTtWGsCj5NYirpaA1BuwDjUVy6LHfTQLZKpTsfLnJURN3t7aIqt.T7pUBdp507p6EP0P1Z0pSQExwbTJKlftMvMh1cq2bI5uEY7eZLz3ShCTblaY8AVzlCjc,a0XWIyjkU8Lc5tDyCbTtWGsCj5NYirpaA1BuwDjUVy6LHfTQLZKpTsfLnJURN3t7aIqt.VsewsTRWPJw52kvXd5Rc6Pefmw9KaWkL5tneRgIvzGqvJNrXhT0lTEnfAidFyJrPZZPE,tpDAhG0zUl.gcBtaiO2Ox()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, GUgccjJtjJ.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Rp5lo6l6F7[2],tpDAhG0zUl.VpSQw46ypp(Convert.FromBase64String(Rp5lo6l6F7[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: BLACKSUPER X.exe.0.dr, 6y6fTLfdmw.cs |
High entropy of concatenated method names: 'r1pE7cxAi3', 'leUKedZ8We', 'f1y2ifNPgq', 'bWirCDm5tCoJAueejbZUoAml9i3IX6hhOHcRw8Ni3dmKHQ2uplSY9PX1oxTTtSItxtqLvnNfCUPpp', 'Ufm2NbBWFFUJluMp1pQ7', '_1IfTyBLLBGCPGzQjdLJ7', 'Bow0iJ0WkmQmLKCzmfrf', 'viXhBtxHrSIWsh6BsCWH', 'N4Hg7Akgr7RQbYxVdIvS', 'oFCWSJmO6zWON5T7JNvw' |
Source: BLACKSUPER X.exe.0.dr, HGK41wUbpnbAJKkqXT5m1RUGLtrCjERgv4S3U45gom3hlGxjzKRGYtj72FjsSjZ4BP7SDymwVtxo2pnQrh.cs |
High entropy of concatenated method names: 'Equals', 'GetHashCode', 'GetType', 'ToString', 'Create__Instance__', 'Dispose__Instance__', 'ZwN4yuWNRde3fqG8wbmCi241tDr', 'xhgKOfLcxuNWikE7Z4i8y6Mud81', 'AID4WqfPr1DUu8TJuHvjLWkm4lM', 'NUm2yOsuOyb9yhggxzlRONTzVn3' |
Source: BLACKSUPER X.exe.0.dr, ErDSEmjKOU.cs |
High entropy of concatenated method names: '_85jw7v8ahg', 'pqbOR3hCLygYVdNL7vbNnmUUT8V1ULI0oOAcaJsFduBHBu6zYETViqVIMe5h', '_35xXSt1vBIliGX7KrzW4HoRwGXasNzmWPjO0fYQoVySp84SvcVgR5NBChApE', 'bwR1ZQ4yhHjNRGLnQgxESC07ECdQpu4PqRNJK0AYp6QOqnOfe4jefE11pTGq', 'Wh247KdpiQv4UUVEPozh7kULebWztqasCKxBJvSzdNV4kxyxfYXLUyGTOMz1' |
Source: BLACKSUPER X.exe.0.dr, GUgccjJtjJ.cs |
High entropy of concatenated method names: '_5BuAtO1BOY', 'e59VesoClT', 'Mrb22HR30q', 'ctbCX7z6KO', 'SoGW4iJen1', 'huexvCvWye', 'wjUywfnS3E', 'UIrPwhbo6o', 'mZ4RUgPZM6', 'dT2Fzruxk2' |
Source: BLACKSUPER X.exe.0.dr, tpDAhG0zUl.cs |
High entropy of concatenated method names: 'EPw49eRJh5', 'se8fVe7jL8', 'XBaVO5EGTW', 'R5BPXXXfsU', 'UajYYsAZEA', 'rJZGYY0taE', '_4MzPbwUjeC', '_3skLWU8FHH', 'ZWft8eomYs', 'Hq7h9DJ9wv' |
Source: BLACKSUPER X.exe.0.dr, P2Vqq9xwoV.cs |
High entropy of concatenated method names: 'ORvjTTLwKq', 'mTYkfW3UWB', 'gnlBzsfBeV', 'veqXNgWGfk', 'TkAgxOp7OKlAyqYvvs2v8CubsxYb6AMivnnZU4u6TUdjq', 'Dyj528U9STg0sVox3191SsGkv8KnqVvQBlQu0FCBycp2T', 'StMlnb7c4Z9xV3mTCQQZJRXkXUxr5MYVSzIC3pm4qmUNv', 'psD1EP5HV49xlYVAinlNxSuKMSHVjwkTVbQcoxCvUM0gG', 'Y3vZqIeQQQ0hBXYPvWQF7OLGnW51wTezDYH5xn2bFrYA9', 'jShWleb5BLHS2pu2fN2Wsxu7OObfm5jscXvUZilt7dMKh' |
Source: BLACKSUPER X.exe.0.dr, dbUysTjE0ENnFMBRDntG94GeNuwRYMkducDkPzxsgNXNaovfgGmW810rO1JUq62gGg8g.cs |
High entropy of concatenated method names: 'TIbCNkcYyxuH9eL0ReWeGjNJcsx1YCanlAadyCevWS0cFYBR1K3JB99P2PWaqGuYuSQP', 'zX0ekSmTMBfTkaj40b69wGiz5GEL9OBvkgeCXZ5JerZZGeq66pXcr5ZRhU2pyJasygOA', '_30YJyjl2hLsQcB63fpcumhMkh45NyIXa5EWMXB5IdS0PZKQjr6PId7zOTyBBt3oe2FDc', 'FLLwHzwPXN6GglZILDJyjnoXDvBjiH04eB5UVh0zhcLGHnZ0gy3cHW2NrrMNnUp8tzzD', '_68o6uFW7msbGoUvfIbGEJKd1thvuaQVejXQVJOLtC3wVAzDwzF4zkaNUNykGJyd8kUUr', '_9H5NEYXIU8hWslae1Mgr5S3nhYTjkaYRdS1uchi46XZ64x8foVJHf4cllmXTv6uHIgVC', 'ElKXm4mN3IChSqVCnzICSdFgQG1NW12uAo6fYv44ecPOtj2S1X2ojuEb8g8Ma6Dk5Wvq', 'y6SLzeOwug7tygveKfaUgTuIoXEIchFRPm1TQ9uszdnThbjCBg1IiJkDjppNcmEX4CSc', 'htEXgwEFBnsVY3em3b67LblZ3eWG6FecG3ZJzBrndm9IKj27xEApNkk0liWf1UAuRi5U', '_5y5lJS2i0ny21jqL2roNHnCj8mL9f1NcYojpF4WCd5QCYT4DN0j6Oxzsi1oH1LlOXbQF' |
Source: BLACKSUPER X.exe.0.dr, HZi2QofiYG.cs |
High entropy of concatenated method names: 'T4SpxDr8NY', 'ToUOouwhj2Q2kIMkNjzebcjiLsDcNYxl7Js7wE3HnKUm9', 'qA4ugixNt7zMxcx61mjLzBpKv3Qj0hMp8pgOrlL6qsQBb', 't5y7kZYLRZvx2VQxUYFlDMVOOtZ6NmMz0irQBrzqS4eSr', '_1KDw1rQLHBRmlAh25BiKNYcVR2XsIg6iSsOBqmTUdSm05' |
Source: BLACKSUPER X.exe.0.dr, PY7JtnPMei.cs |
High entropy of concatenated method names: 'PIzi7fb2RQ', 'Y174dhc0Sy', 'tpymlfR0lq', 'v8a2lNM4Pk', '_88UlDrGuYM', 'yuQ8kIGqru', 'SyVUy8RwjX', 'FDpj49fNfe', '_6J8O3NCmM9', 'MifUmqNUvZ' |
Source: BLACKSUPER X.exe.0.dr, n3KIdyQiO9.cs |
High entropy of concatenated method names: '_9WHRSclXIP', 'eo7Gv6raPY', 'IGwpVYsrCP', 'MGWe0a8cvY', 'aKsxOtSHnl', 'p8PCcdpIXJ', 'UPkVeQIWtZ', 'DmGhX3DYyb', 'W4Qp0T1L6g', 'tAVZBIkjFZ' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, 6y6fTLfdmw.cs |
High entropy of concatenated method names: 'r1pE7cxAi3', 'leUKedZ8We', 'f1y2ifNPgq', 'bWirCDm5tCoJAueejbZUoAml9i3IX6hhOHcRw8Ni3dmKHQ2uplSY9PX1oxTTtSItxtqLvnNfCUPpp', 'Ufm2NbBWFFUJluMp1pQ7', '_1IfTyBLLBGCPGzQjdLJ7', 'Bow0iJ0WkmQmLKCzmfrf', 'viXhBtxHrSIWsh6BsCWH', 'N4Hg7Akgr7RQbYxVdIvS', 'oFCWSJmO6zWON5T7JNvw' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, HGK41wUbpnbAJKkqXT5m1RUGLtrCjERgv4S3U45gom3hlGxjzKRGYtj72FjsSjZ4BP7SDymwVtxo2pnQrh.cs |
High entropy of concatenated method names: 'Equals', 'GetHashCode', 'GetType', 'ToString', 'Create__Instance__', 'Dispose__Instance__', 'ZwN4yuWNRde3fqG8wbmCi241tDr', 'xhgKOfLcxuNWikE7Z4i8y6Mud81', 'AID4WqfPr1DUu8TJuHvjLWkm4lM', 'NUm2yOsuOyb9yhggxzlRONTzVn3' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, ErDSEmjKOU.cs |
High entropy of concatenated method names: '_85jw7v8ahg', 'pqbOR3hCLygYVdNL7vbNnmUUT8V1ULI0oOAcaJsFduBHBu6zYETViqVIMe5h', '_35xXSt1vBIliGX7KrzW4HoRwGXasNzmWPjO0fYQoVySp84SvcVgR5NBChApE', 'bwR1ZQ4yhHjNRGLnQgxESC07ECdQpu4PqRNJK0AYp6QOqnOfe4jefE11pTGq', 'Wh247KdpiQv4UUVEPozh7kULebWztqasCKxBJvSzdNV4kxyxfYXLUyGTOMz1' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, GUgccjJtjJ.cs |
High entropy of concatenated method names: '_5BuAtO1BOY', 'e59VesoClT', 'Mrb22HR30q', 'ctbCX7z6KO', 'SoGW4iJen1', 'huexvCvWye', 'wjUywfnS3E', 'UIrPwhbo6o', 'mZ4RUgPZM6', 'dT2Fzruxk2' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, tpDAhG0zUl.cs |
High entropy of concatenated method names: 'EPw49eRJh5', 'se8fVe7jL8', 'XBaVO5EGTW', 'R5BPXXXfsU', 'UajYYsAZEA', 'rJZGYY0taE', '_4MzPbwUjeC', '_3skLWU8FHH', 'ZWft8eomYs', 'Hq7h9DJ9wv' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, P2Vqq9xwoV.cs |
High entropy of concatenated method names: 'ORvjTTLwKq', 'mTYkfW3UWB', 'gnlBzsfBeV', 'veqXNgWGfk', 'TkAgxOp7OKlAyqYvvs2v8CubsxYb6AMivnnZU4u6TUdjq', 'Dyj528U9STg0sVox3191SsGkv8KnqVvQBlQu0FCBycp2T', 'StMlnb7c4Z9xV3mTCQQZJRXkXUxr5MYVSzIC3pm4qmUNv', 'psD1EP5HV49xlYVAinlNxSuKMSHVjwkTVbQcoxCvUM0gG', 'Y3vZqIeQQQ0hBXYPvWQF7OLGnW51wTezDYH5xn2bFrYA9', 'jShWleb5BLHS2pu2fN2Wsxu7OObfm5jscXvUZilt7dMKh' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, dbUysTjE0ENnFMBRDntG94GeNuwRYMkducDkPzxsgNXNaovfgGmW810rO1JUq62gGg8g.cs |
High entropy of concatenated method names: 'TIbCNkcYyxuH9eL0ReWeGjNJcsx1YCanlAadyCevWS0cFYBR1K3JB99P2PWaqGuYuSQP', 'zX0ekSmTMBfTkaj40b69wGiz5GEL9OBvkgeCXZ5JerZZGeq66pXcr5ZRhU2pyJasygOA', '_30YJyjl2hLsQcB63fpcumhMkh45NyIXa5EWMXB5IdS0PZKQjr6PId7zOTyBBt3oe2FDc', 'FLLwHzwPXN6GglZILDJyjnoXDvBjiH04eB5UVh0zhcLGHnZ0gy3cHW2NrrMNnUp8tzzD', '_68o6uFW7msbGoUvfIbGEJKd1thvuaQVejXQVJOLtC3wVAzDwzF4zkaNUNykGJyd8kUUr', '_9H5NEYXIU8hWslae1Mgr5S3nhYTjkaYRdS1uchi46XZ64x8foVJHf4cllmXTv6uHIgVC', 'ElKXm4mN3IChSqVCnzICSdFgQG1NW12uAo6fYv44ecPOtj2S1X2ojuEb8g8Ma6Dk5Wvq', 'y6SLzeOwug7tygveKfaUgTuIoXEIchFRPm1TQ9uszdnThbjCBg1IiJkDjppNcmEX4CSc', 'htEXgwEFBnsVY3em3b67LblZ3eWG6FecG3ZJzBrndm9IKj27xEApNkk0liWf1UAuRi5U', '_5y5lJS2i0ny21jqL2roNHnCj8mL9f1NcYojpF4WCd5QCYT4DN0j6Oxzsi1oH1LlOXbQF' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, HZi2QofiYG.cs |
High entropy of concatenated method names: 'T4SpxDr8NY', 'ToUOouwhj2Q2kIMkNjzebcjiLsDcNYxl7Js7wE3HnKUm9', 'qA4ugixNt7zMxcx61mjLzBpKv3Qj0hMp8pgOrlL6qsQBb', 't5y7kZYLRZvx2VQxUYFlDMVOOtZ6NmMz0irQBrzqS4eSr', '_1KDw1rQLHBRmlAh25BiKNYcVR2XsIg6iSsOBqmTUdSm05' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, PY7JtnPMei.cs |
High entropy of concatenated method names: 'PIzi7fb2RQ', 'Y174dhc0Sy', 'tpymlfR0lq', 'v8a2lNM4Pk', '_88UlDrGuYM', 'yuQ8kIGqru', 'SyVUy8RwjX', 'FDpj49fNfe', '_6J8O3NCmM9', 'MifUmqNUvZ' |
Source: 0.2.XSLHv0kxy7.exe.2fbf170.1.raw.unpack, n3KIdyQiO9.cs |
High entropy of concatenated method names: '_9WHRSclXIP', 'eo7Gv6raPY', 'IGwpVYsrCP', 'MGWe0a8cvY', 'aKsxOtSHnl', 'p8PCcdpIXJ', 'UPkVeQIWtZ', 'DmGhX3DYyb', 'W4Qp0T1L6g', 'tAVZBIkjFZ' |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\XSLHv0kxy7.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\BLACKSUPER X.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: Amcache.hve.8.dr |
Binary or memory string: VMware |
Source: Amcache.hve.8.dr |
Binary or memory string: VMware Virtual USB Mouse |
Source: Amcache.hve.8.dr |
Binary or memory string: vmci.syshbin |
Source: Amcache.hve.8.dr |
Binary or memory string: VMware, Inc. |
Source: Amcache.hve.8.dr |
Binary or memory string: VMware20,1hbin@ |
Source: Amcache.hve.8.dr |
Binary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563 |
Source: Amcache.hve.8.dr |
Binary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Amcache.hve.8.dr |
Binary or memory string: .Z$c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.8.dr |
Binary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.8.dr |
Binary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev |
Source: Amcache.hve.8.dr |
Binary or memory string: c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.8.dr |
Binary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: BLACKSUPER X.exe, 00000003.00000002.1999322026.000000001BAC8000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: Amcache.hve.8.dr |
Binary or memory string: vmci.sys |
Source: Amcache.hve.8.dr |
Binary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0 |
Source: Amcache.hve.8.dr |
Binary or memory string: vmci.syshbin` |
Source: BLACKSUPER X.exe.0.dr |
Binary or memory string: vmware |
Source: Amcache.hve.8.dr |
Binary or memory string: \driver\vmci,\driver\pci |
Source: Amcache.hve.8.dr |
Binary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.8.dr |
Binary or memory string: VMware20,1 |
Source: Amcache.hve.8.dr |
Binary or memory string: Microsoft Hyper-V Generation Counter |
Source: Amcache.hve.8.dr |
Binary or memory string: NECVMWar VMware SATA CD00 |
Source: Amcache.hve.8.dr |
Binary or memory string: VMware Virtual disk SCSI Disk Device |
Source: Amcache.hve.8.dr |
Binary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom |
Source: Amcache.hve.8.dr |
Binary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk |
Source: Amcache.hve.8.dr |
Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver |
Source: Amcache.hve.8.dr |
Binary or memory string: VMware PCI VMCI Bus Device |
Source: Amcache.hve.8.dr |
Binary or memory string: VMware VMCI Bus Device |
Source: Amcache.hve.8.dr |
Binary or memory string: VMware Virtual RAM |
Source: Amcache.hve.8.dr |
Binary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1 |
Source: Amcache.hve.8.dr |
Binary or memory string: vmci.inf_amd64_68ed49469341f563 |