Windows Analysis Report
MemProfilerInstaller5_7_28.exe

Overview

General Information

Sample name: MemProfilerInstaller5_7_28.exe
Analysis ID: 1446966
MD5: 7e45c0ea667dcf7b44cc304a0f159d32
SHA1: d38693fb82dd2132fc314708e8fabb3aebe07668
SHA256: 9c249afa63fee4ecf8feab4512bbefba68949da7083349d26ffa439c06eab3c3
Infos:

Detection

Score: 8
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
Found evasive API chain (date check)
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Uses the system / local time for branch decision (may execute only at specific dates)

Classification

Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00579F8F DecryptFileW, 0_2_00579F8F
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0059F340 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError, 0_2_0059F340
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00579D74 DecryptFileW,DecryptFileW, 0_2_00579D74
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00139F8F DecryptFileW, 1_2_00139F8F
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0015F340 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError, 1_2_0015F340
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00139D74 DecryptFileW,DecryptFileW, 1_2_00139D74
Source: MemProfilerInstaller5_7_28.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: MemProfilerInstaller5_7_28.exe Static PE information: certificate valid
Source: MemProfilerInstaller5_7_28.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\agent\_work\66\s\build\ship\x86\mbahost.pdb source: MemProfilerInstaller5_7_28.exe, 00000001.00000002.2980291916.000000006CBE4000.00000002.00000001.01000000.00000007.sdmp, mbahost.dll.1.dr
Source: Binary string: C:\agent\_work\66\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdbP source: Microsoft.Deployment.WindowsInstaller.dll.1.dr
Source: Binary string: C:\agent\_work\66\s\build\ship\x86\burn.pdb source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr
Source: Binary string: C:\agent\_work\66\s\build\obj\ship\x86\core\BootstrapperCore.pdb source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe, 00000001.00000002.2977641737.00000000030D2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.1.dr
Source: Binary string: C:\Sci\Build\NetMemProfiler\Installer\MemProfilerBootstrapper\obj\Release\MemProfilerBootstrapper.pdb source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe, 00000001.00000002.2978694391.0000000005F32000.00000002.00000001.01000000.0000000B.sdmp, MemProfilerBootstrapper.dll.1.dr
Source: Binary string: C:\agent\_work\66\s\build\ship\x86\WixStdBA.pdb source: mbapreq.dll.1.dr
Source: Binary string: C:\agent\_work\66\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb source: Microsoft.Deployment.WindowsInstaller.dll.1.dr
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00579A1D FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 0_2_00579A1D
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005A3C72 FindFirstFileW,FindClose, 0_2_005A3C72
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00563D4E GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose, 0_2_00563D4E
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00139A1D FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 1_2_00139A1D
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00163C72 FindFirstFileW,FindClose, 1_2_00163C72
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00123D4E GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose, 1_2_00123D4E
Source: MemProfilerInstaller5_7_28.exe String found in binary or memory: http://appsyndication.org/2006/appsyn
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: http://appsyndication.org/2006/appsynapplicationc:
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0=
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
Source: MemProfilerInstaller5_7_28.exe, 00000001.00000002.2977836131.0000000003911000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://defaultcontainer/MemProfilerBootstrapper;component/views/wizardheadercontrol.xamld
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: http://ocsp.comodoca.com0
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://ocsp.digicert.com0C
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://ocsp.digicert.com0K
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://ocsp.digicert.com0N
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://ocsp.digicert.com0O
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: http://ocsp.sectigo.com0
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://wixtoolset.org
Source: MemProfilerInstaller5_7_28.exe String found in binary or memory: http://wixtoolset.org/
Source: MemProfilerInstaller5_7_28.exe, 00000001.00000002.2977641737.00000000030D2000.00000002.00000001.01000000.0000000A.sdmp, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe, 00000001.00000002.2977641737.00000000030D2000.00000002.00000001.01000000.0000000A.sdmp, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://wixtoolset.org/news/
Source: MemProfilerInstaller5_7_28.exe, Microsoft.Deployment.WindowsInstaller.dll.1.dr String found in binary or memory: http://wixtoolset.org/releases/
Source: MemProfilerInstaller5_7_28.exe, 00000001.00000002.2977641737.00000000030D2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.1.dr String found in binary or memory: http://wixtoolset.org/releases/SCreating
Source: mbapreq.thm.1.dr String found in binary or memory: http://wixtoolset.org/schemas/thmutil/2010
Source: MemProfilerInstaller5_7_28.exe String found in binary or memory: http://wixtoolset.org/telemetry/v
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: https://memprofiler.com
Source: MemProfilerInstaller5_7_28.exe String found in binary or memory: https://memprofiler.com/eula
Source: MemProfilerInstaller5_7_28.exe, 00000001.00000002.2978694391.0000000005F32000.00000002.00000001.01000000.0000000B.sdmp, MemProfilerBootstrapper.dll.1.dr String found in binary or memory: https://memprofiler.com/eula;Failed
Source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr String found in binary or memory: https://sectigo.com/CPS0
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: https://www.digicert.com/CPS0
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0058C01F 0_2_0058C01F
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005901A6 0_2_005901A6
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005662CC 0_2_005662CC
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0059A28E 0_2_0059A28E
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00590461 0_2_00590461
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00592413 0_2_00592413
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00592642 0_2_00592642
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0059E73C 0_2_0059E73C
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0058F8C3 0_2_0058F8C3
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0058FC35 0_2_0058FC35
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00599DE0 0_2_00599DE0
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0058FEDF 0_2_0058FEDF
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00583F71 0_2_00583F71
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0014C01F 1_2_0014C01F
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_001501A6 1_2_001501A6
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0015A28E 1_2_0015A28E
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_001262CC 1_2_001262CC
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00152413 1_2_00152413
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00150461 1_2_00150461
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00152642 1_2_00152642
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0015E73C 1_2_0015E73C
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0014F8C3 1_2_0014F8C3
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0014FC35 1_2_0014FC35
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00159DE0 1_2_00159DE0
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0014FEDF 1_2_0014FEDF
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00143F71 1_2_00143F71
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_05F3538E 1_2_05F3538E
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_6CBDD880 1_2_6CBDD880
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_6CBDDD2E 1_2_6CBDDD2E
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_6CBE2918 1_2_6CBE2918
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_6CBD7117 1_2_6CBD7117
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_6CBD6EE8 1_2_6CBD6EE8
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: String function: 005A2B5D appears 81 times
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: String function: 0059FFF0 appears 34 times
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: String function: 005638BA appears 498 times
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: String function: 0059FB09 appears 680 times
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: String function: 00562022 appears 54 times
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: String function: 00162B5D appears 79 times
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: String function: 001238BA appears 500 times
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: String function: 00122022 appears 54 times
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: String function: 0015FFF0 appears 34 times
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: String function: 0015FB09 appears 682 times
Source: MemProfilerInstaller5_7_28.exe Binary or memory string: OriginalFilename vs MemProfilerInstaller5_7_28.exe
Source: MemProfilerInstaller5_7_28.exe, 00000001.00000002.2975026490.00000000006C7000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs MemProfilerInstaller5_7_28.exe
Source: MemProfilerInstaller5_7_28.exe, 00000001.00000002.2980339637.000000006CBEE000.00000002.00000001.01000000.00000007.sdmp Binary or memory string: OriginalFilenamembahost.dll\ vs MemProfilerInstaller5_7_28.exe
Source: MemProfilerInstaller5_7_28.exe, 00000001.00000002.2977684399.00000000030E4000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: OriginalFilenameBootstrapperCore.dll\ vs MemProfilerInstaller5_7_28.exe
Source: MemProfilerInstaller5_7_28.exe, 00000001.00000002.2978694391.0000000005F32000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: OriginalFilenameMemProfilerBootstrapper.dllP vs MemProfilerInstaller5_7_28.exe
Source: MemProfilerInstaller5_7_28.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: classification engine Classification label: clean8.winEXE@3/35@0/0
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00562078 FormatMessageW,GetLastError,LocalFree, 0_2_00562078
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00564639 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle, 0_2_00564639
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00124639 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle, 1_2_00124639
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005A28BD GetModuleHandleA,GetLastError,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CoCreateInstance,ExitProcess, 0_2_005A28BD
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005868EE ChangeServiceConfigW,GetLastError, 0_2_005868EE
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Mutant created: NULL
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\ Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Command line argument: cabinet.dll 0_2_00561070
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Command line argument: msi.dll 0_2_00561070
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Command line argument: version.dll 0_2_00561070
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Command line argument: wininet.dll 0_2_00561070
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Command line argument: comres.dll 0_2_00561070
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Command line argument: clbcatq.dll 0_2_00561070
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Command line argument: msasn1.dll 0_2_00561070
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Command line argument: crypt32.dll 0_2_00561070
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Command line argument: feclient.dll 0_2_00561070
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Command line argument: cabinet.dll 0_2_00561070
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Command line argument: cabinet.dll 1_2_00121070
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Command line argument: msi.dll 1_2_00121070
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Command line argument: version.dll 1_2_00121070
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Command line argument: wininet.dll 1_2_00121070
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Command line argument: comres.dll 1_2_00121070
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Command line argument: clbcatq.dll 1_2_00121070
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Command line argument: msasn1.dll 1_2_00121070
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Command line argument: crypt32.dll 1_2_00121070
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Command line argument: feclient.dll 1_2_00121070
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Command line argument: cabinet.dll 1_2_00121070
Source: MemProfilerInstaller5_7_28.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: MemProfilerInstaller5_7_28.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: MemProfilerInstaller5_7_28.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: MemProfilerInstaller5_7_28.exe String found in binary or memory: is already installed. Do you want to re-install
Source: MemProfilerInstaller5_7_28.exe String found in binary or memory: resources/installerviewresources.baml
Source: MemProfilerInstaller5_7_28.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe File read: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe "C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe"
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Process created: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe "C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe" -burn.clean.room="C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe" -burn.filehandle.attached=544 -burn.filehandle.self=536
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Process created: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe "C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe" -burn.clean.room="C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe" -burn.filehandle.attached=544 -burn.filehandle.self=536 Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: msi.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: feclient.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: msi.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: feclient.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: msvcp140_clr0400.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: d3d9.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: msctfui.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: d3dcompiler_47.dll Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InProcServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: MemProfilerInstaller5_7_28.exe Static PE information: certificate valid
Source: MemProfilerInstaller5_7_28.exe Static file information: File size 101670752 > 1048576
Source: MemProfilerInstaller5_7_28.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: MemProfilerInstaller5_7_28.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: MemProfilerInstaller5_7_28.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: MemProfilerInstaller5_7_28.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: MemProfilerInstaller5_7_28.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: MemProfilerInstaller5_7_28.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: MemProfilerInstaller5_7_28.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: MemProfilerInstaller5_7_28.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\agent\_work\66\s\build\ship\x86\mbahost.pdb source: MemProfilerInstaller5_7_28.exe, 00000001.00000002.2980291916.000000006CBE4000.00000002.00000001.01000000.00000007.sdmp, mbahost.dll.1.dr
Source: Binary string: C:\agent\_work\66\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdbP source: Microsoft.Deployment.WindowsInstaller.dll.1.dr
Source: Binary string: C:\agent\_work\66\s\build\ship\x86\burn.pdb source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe.0.dr
Source: Binary string: C:\agent\_work\66\s\build\obj\ship\x86\core\BootstrapperCore.pdb source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe, 00000001.00000002.2977641737.00000000030D2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.1.dr
Source: Binary string: C:\Sci\Build\NetMemProfiler\Installer\MemProfilerBootstrapper\obj\Release\MemProfilerBootstrapper.pdb source: MemProfilerInstaller5_7_28.exe, MemProfilerInstaller5_7_28.exe, 00000001.00000002.2978694391.0000000005F32000.00000002.00000001.01000000.0000000B.sdmp, MemProfilerBootstrapper.dll.1.dr
Source: Binary string: C:\agent\_work\66\s\build\ship\x86\WixStdBA.pdb source: mbapreq.dll.1.dr
Source: Binary string: C:\agent\_work\66\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb source: Microsoft.Deployment.WindowsInstaller.dll.1.dr
Source: MemProfilerInstaller5_7_28.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: MemProfilerInstaller5_7_28.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: MemProfilerInstaller5_7_28.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: MemProfilerInstaller5_7_28.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: MemProfilerInstaller5_7_28.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: MemProfilerBootstrapper.dll.1.dr Static PE information: 0xED4615F6 [Wed Feb 22 23:55:34 2096 UTC]
Source: MemProfilerInstaller5_7_28.exe Static PE information: section name: .wixburn
Source: MemProfilerInstaller5_7_28.exe.0.dr Static PE information: section name: .wixburn
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0058E806 push ecx; ret 0_2_0058E819
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0014E806 push ecx; ret 1_2_0014E819
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_6CBD4476 push ecx; ret 1_2_6CBD4489
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_02AF50B2 pushfd ; iretd 1_2_02AF50B1
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_02AF506A pushfd ; iretd 1_2_02AF50B1
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_02AF5062 pushad ; iretd 1_2_02AF5069
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_02AF2642 push D000005Fh; iretd 1_2_02AF2661
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_02AF2592 pushfd ; iretd 1_2_02AF2591
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_02AF256B pushfd ; iretd 1_2_02AF2591
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_02AF5550 push esp; retf 1_2_02AF5559
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\BootstrapperCore.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\mbapreq.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\Microsoft.Deployment.WindowsInstaller.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\MemProfilerBootstrapper.dll Jump to dropped file
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\mbahost.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\BootstrapperCore.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\mbapreq.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\Microsoft.Deployment.WindowsInstaller.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\MemProfilerBootstrapper.dll Jump to dropped file
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe File created: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\mbahost.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Memory allocated: 2A90000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Memory allocated: 3910000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Memory allocated: 5910000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Dropped PE file which has not been started: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\BootstrapperCore.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Dropped PE file which has not been started: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\mbapreq.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Dropped PE file which has not been started: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\Microsoft.Deployment.WindowsInstaller.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Dropped PE file which has not been started: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\MemProfilerBootstrapper.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Dropped PE file which has not been started: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\mbahost.dll Jump to dropped file
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Evasive API call chain: GetLocalTime,DecisionNodes
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Check user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Check user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe API coverage: 8.9 %
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0059F79E GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 0059F839h 0_2_0059F79E
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0059F79E GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 0059F832h 0_2_0059F79E
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0015F79E GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 0015F839h 1_2_0015F79E
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0015F79E GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 0015F832h 1_2_0015F79E
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00579A1D FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 0_2_00579A1D
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005A3C72 FindFirstFileW,FindClose, 0_2_005A3C72
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00563D4E GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose, 0_2_00563D4E
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00139A1D FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 1_2_00139A1D
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00163C72 FindFirstFileW,FindClose, 1_2_00163C72
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00123D4E GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose, 1_2_00123D4E
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005A8EF4 VirtualQuery,GetSystemInfo, 0_2_005A8EF4
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe API call chain: ExitProcess graph end node
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005934A2 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_005934A2
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00594104 mov eax, dword ptr fs:[00000030h] 0_2_00594104
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_00154104 mov eax, dword ptr fs:[00000030h] 1_2_00154104
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_6CBD8FD6 mov eax, dword ptr fs:[00000030h] 1_2_6CBD8FD6
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005639DF GetProcessHeap,RtlAllocateHeap, 0_2_005639DF
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0058E0A8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_0058E0A8
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005934A2 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_005934A2
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0058E574 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_0058E574
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0058E707 SetUnhandledExceptionFilter, 0_2_0058E707
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0014E0A8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 1_2_0014E0A8
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_001534A2 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_001534A2
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0014E574 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_0014E574
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_0014E707 SetUnhandledExceptionFilter, 1_2_0014E707
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_6CBD448C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 1_2_6CBD448C
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_6CBD42B6 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_6CBD42B6
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Code function: 1_2_6CBD7F77 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_6CBD7F77
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Process created: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe "C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe" -burn.clean.room="C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe" -burn.filehandle.attached=544 -burn.filehandle.self=536 Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005A0FA6 InitializeSecurityDescriptor,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,SetEntriesInAclA,SetSecurityDescriptorOwner,GetLastError,SetSecurityDescriptorGroup,GetLastError,SetSecurityDescriptorDacl,GetLastError,CoInitializeSecurity,LocalFree, 0_2_005A0FA6
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005A32B9 AllocateAndInitializeSid,CheckTokenMembership, 0_2_005A32B9
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0058E937 cpuid 0_2_0058E937
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\BootstrapperCore.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Temp\{2CFE9258-2647-47E2-8C0C-66233E78E1BF}\.ba\MemProfilerBootstrapper.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00574E6A ConvertStringSecurityDescriptorToSecurityDescriptorW,GetLastError,CreateNamedPipeW,GetLastError,CreateNamedPipeW,GetLastError,CloseHandle,LocalFree, 0_2_00574E6A
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_0056605F GetSystemTime,GetDateFormatW,GetLastError,GetLastError,GetDateFormatW,GetLastError, 0_2_0056605F
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_00566203 GetUserNameW,GetLastError, 0_2_00566203
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005A8039 GetTimeZoneInformation,SystemTimeToTzSpecificLocalTime, 0_2_005A8039
Source: C:\Users\user\Desktop\MemProfilerInstaller5_7_28.exe Code function: 0_2_005651D2 GetModuleHandleW,CoInitializeEx,GetVersionExW,GetLastError,CoUninitialize, 0_2_005651D2
Source: C:\Windows\Temp\{E6BCEB9A-789C-4B61-A31A-88AF3D699066}\.cr\MemProfilerInstaller5_7_28.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
No contacted IP infos