Windows Analysis Report
VDR Explorer Setup.exe

Overview

General Information

Sample name: VDR Explorer Setup.exe
Analysis ID: 1447258
MD5: 12c58f5fa1774cef7fce2116da0574fc
SHA1: d9d7af7807f448ea16b01bcf8fd752973f1f0dba
SHA256: 7cacf6ee028bff02d925f684450c9bd11db7fe1aab6aa216fac10108936cf25b
Infos:

Detection

Score: 2
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Drops PE files
Found dropped PE file which has not been started or loaded
Installs a raw input device (often for capturing keystrokes)
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

Source: is-IG155.tmp.2.dr Binary or memory string: -----BEGIN PUBLIC KEY----- memstr_687905f9-9
Source: VDR Explorer Setup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: VDR Explorer Setup.exe Static PE information: certificate valid
Source: VDR Explorer Setup.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\Jenkins\workspace\workspace\VDRExplorer_master\src\VDRExtraction\Release\VDRExtraction.pdb source: is-5OONJ.tmp.2.dr
Source: Binary string: C:\Jenkins\workspace\workspace\VDRExplorer_master\src\Libs\LiteZip\Release\LiteZip.pdb source: is-61L3J.tmp.2.dr
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavcodec\avcodec-58.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000059E7000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libswresample\swresample-3.pdb source: is-TENQ4.tmp.2.dr
Source: Binary string: C:\Jenkins\workspace\workspace\VDRExplorer_master\src\VDRExplorerAdminMode\Release\VDRExplorerAdminMode.pdbp source: is-V4VS3.tmp.2.dr
Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MT /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_CPUID_OBJ -DOPENSSL_BN_ASM_PART_WORDS -DOPENSSL_IA32_SSE2 -DOPENSSL_BN_ASM_MONT -DOPENSSL_BN_ASM_GF2m -DSHA1_ASM -DSHA256_ASM -DSHA512_ASM -DRC4_ASM -DMD5_ASM -DRMD160_ASM -DAESNI_ASM -DVPAES_ASM -DWHIRLPOOL_ASM -DGHASH_ASM -DECP_NISTZ256_ASM -DPOLY1305_ASM source: is-IG155.tmp.2.dr
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavutil\avutil-56.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000055B6000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ?crypto\stack\stack.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MT /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_CPUID_OBJ -DOPENSSL_BN_ASM_PART_WORDS -DOPENSSL_IA32_SSE2 -DOPENSSL_BN_ASM_MONT -DOPENSSL_BN_ASM_GF2m -DSHA1_ASM -DSHA256_ASM -DSHA512_ASM -DRC4_ASM -DMD5_ASM -DRMD160_ASM -DAESNI_ASM -DVPAES_ASM -DWHIRLPOOL_ASM -DGHASH_ASM -DECP_NISTZ256_ASM -DPOLY1305_ASMcrypto\ex_data.c source: is-IG155.tmp.2.dr
Source: Binary string: C:\Jenkins\workspace\workspace\VDRExplorer_master\src\VDRExplorerAdminMode\Release\VDRExplorerAdminMode.pdb source: is-V4VS3.tmp.2.dr
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavformat\avformat-58.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000057A9000.00000004.00001000.00020000.00000000.sdmp, is-64HQM.tmp.2.dr
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavfilter\avfilter-7.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.0000000005897000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\_proj\WinVDR\Packets\SDL\Src\VisualC\Win32\Release\SDL2.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000055B6000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libswscale\swscale-5.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000055B6000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavcodec\avcodec-58.pdb[ source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000059E7000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavdevice\avdevice-58.pdb source: is-LTTGC.tmp.2.dr
Source: Binary string: C:\Jenkins\workspace\workspace\VDRExplorer_master\src\Libs\mpglib.dll\Release\mpglib.pdb source: is-OJCQN.tmp.2.dr
Source: is-IG155.tmp.2.dr String found in binary or memory: http://%IP%:%PORT%/remote_access_ctrl.cgi?username=%USERNAME%&hashed_pw=%PASSWORD%
Source: is-IG155.tmp.2.dr String found in binary or memory: http://%IP%:%PORT%/remote_access_ctrl.cgi?username=%USERNAME%&hashed_pw=%PASSWORD%post_action=get_vd
Source: is-IG155.tmp.2.dr String found in binary or memory: http://%IP/vri.php?password=%%&username=%USERNAME%
Source: is-IG155.tmp.2.dr String found in binary or memory: http://%IP/vri.php?password=%%&username=%USERNAME%pwuser10.0.0.1ARG1=ERTpwuser10.0.0.1ARG1=ERT
Source: is-IG155.tmp.2.dr String found in binary or memory: http://%s/cgi-bin/upload_config.exe
Source: is-IG155.tmp.2.dr String found in binary or memory: http://%s/cgi-bin/upload_config.execonfig.vezVdrExplorerConfig
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: http://danelec-marine.com
Source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.0000000005735000.00000004.00001000.00020000.00000000.sdmp, is-64HQM.tmp.2.dr String found in binary or memory: http://dashif.org/guidelines/trickmode
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: http://ocsp.comodoca.com0
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: http://ocsp.sectigo.com0
Source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.0000000005735000.00000004.00001000.00020000.00000000.sdmp, is-64HQM.tmp.2.dr String found in binary or memory: http://standards.iso.org/ittf/PubliclyAvailableStandards/MPEG-DASH_schema_files/DASH-MPD.xsd
Source: is-UH24C.tmp.2.dr String found in binary or memory: http://www.boost.org/users/license.html).
Source: is-ER9AF.tmp.2.dr String found in binary or memory: http://www.codeguru.com/clipboard/simple_clipboard.shtml
Source: is-9BQ2U.tmp.2.dr String found in binary or memory: http://www.codeproject.com/info/cpol10.aspx
Source: VDR Explorer Setup.exe, 00000001.00000003.1763144014.0000000000B31000.00000004.00001000.00020000.00000000.sdmp, VDR Explorer Setup.tmp, 00000002.00000003.1758090738.00000000025A1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.danelec-marine.com
Source: VDR Explorer Setup.exe, 00000001.00000003.1344459769.0000000002570000.00000004.00001000.00020000.00000000.sdmp, VDR Explorer Setup.tmp, 00000002.00000003.1350113218.00000000034A0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.danelec-marine.com:http://www.danelec-marine.com:http://www.danelec-marine.com
Source: VDR Explorer Setup.exe, 00000001.00000003.1763144014.0000000000B31000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.danelec-marine.comA
Source: VDR Explorer Setup.tmp, 00000002.00000003.1758090738.00000000025A1000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.danelec-marine.comQ
Source: is-IG155.tmp.2.dr String found in binary or memory: http://www.ijg.org
Source: is-SBIU6.tmp.2.dr String found in binary or memory: http://www.mpg123.de.
Source: is-V4T4C.tmp.2.dr String found in binary or memory: http://www.naughter.com/
Source: is-SBIU6.tmp.2.dr String found in binary or memory: http://www.rz.uni-frankfurt.de/~pesch)
Source: is-SBIU6.tmp.2.dr String found in binary or memory: http://www.sulaco.org/mp3.
Source: is-IG155.tmp.2.dr String found in binary or memory: https://%IP%:%PORT%/remote-management.php?auth-user=%USERNAME%&auth-pwd=%PASSWORD%
Source: is-10PSV.tmp.2.dr String found in binary or memory: https://curl.haxx.se/docs/copyright.html
Source: is-IG155.tmp.2.dr String found in binary or memory: https://curl.haxx.se/docs/http-cookies.html
Source: VDR Explorer Setup.exe String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: VDR Explorer Setup.exe, VDR Explorer Setup.tmp.1.dr, is-5OONJ.tmp.2.dr, is-IG155.tmp.2.dr, is-OJCQN.tmp.2.dr, is-J0SVD.tmp.2.dr, is-61L3J.tmp.2.dr, is-V4VS3.tmp.2.dr String found in binary or memory: https://sectigo.com/CPS0
Source: VDR Explorer Setup.exe, 00000001.00000003.1345856387.0000000002570000.00000004.00001000.00020000.00000000.sdmp, VDR Explorer Setup.exe, 00000001.00000003.1346320802.000000007FB40000.00000004.00001000.00020000.00000000.sdmp, VDR Explorer Setup.tmp, 00000002.00000000.1347915873.0000000000401000.00000020.00000001.01000000.00000004.sdmp, VDR Explorer Setup.tmp.1.dr, is-J0SVD.tmp.2.dr String found in binary or memory: https://www.innosetup.com/
Source: VDR Explorer Setup.exe, 00000001.00000003.1345856387.0000000002570000.00000004.00001000.00020000.00000000.sdmp, VDR Explorer Setup.exe, 00000001.00000003.1346320802.000000007FB40000.00000004.00001000.00020000.00000000.sdmp, VDR Explorer Setup.tmp, 00000002.00000000.1347915873.0000000000401000.00000020.00000001.01000000.00000004.sdmp, VDR Explorer Setup.tmp.1.dr, is-J0SVD.tmp.2.dr String found in binary or memory: https://www.remobjects.com/ps
Source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000055B6000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: GetRawInputData memstr_28260ce2-6
Source: VDR Explorer Setup.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-J0SVD.tmp.2.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: VDR Explorer Setup.exe, 00000001.00000003.1763144014.0000000000AE8000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamekernel32j% vs VDR Explorer Setup.exe
Source: VDR Explorer Setup.exe, 00000001.00000003.1346320802.000000007FE35000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFileName vs VDR Explorer Setup.exe
Source: VDR Explorer Setup.exe, 00000001.00000000.1344150951.00000000004C6000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFileName vs VDR Explorer Setup.exe
Source: VDR Explorer Setup.exe, 00000001.00000003.1345856387.0000000002668000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFileName vs VDR Explorer Setup.exe
Source: VDR Explorer Setup.exe Binary or memory string: OriginalFileName vs VDR Explorer Setup.exe
Source: VDR Explorer Setup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: VDR Explorer Setup.exe Binary or memory string: .vBPg
Source: classification engine Classification label: clean2.winEXE@3/340@0/0
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Users\user\AppData\Local\Programs Jump to behavior
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe File created: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp Jump to behavior
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File read: C:\Program Files (x86)\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: VDR Explorer Setup.exe String found in binary or memory: /LOADINF="filename"
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe File read: C:\Users\user\Desktop\VDR Explorer Setup.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\VDR Explorer Setup.exe "C:\Users\user\Desktop\VDR Explorer Setup.exe"
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Process created: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp "C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp" /SL5="$1040A,15055123,832512,C:\Users\user\Desktop\VDR Explorer Setup.exe"
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Process created: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp "C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp" /SL5="$1040A,15055123,832512,C:\Users\user\Desktop\VDR Explorer Setup.exe" Jump to behavior
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: msftedit.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: windows.globalization.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: bcp47mrm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: globinputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: windows.ui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: windowmanagementapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: inputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32 Jump to behavior
Source: VDR Explorer.lnk.2.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Common Files\VDR Explorer\VDRExplorerAdminMode.exe
Source: VDR Explorer - No admin rights.lnk.2.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Common Files\VDR Explorer\VDRExplorer.exe
Source: VDR Explorer - Safe mode.lnk.2.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Common Files\VDR Explorer\VDRExplorer.exe
Source: Uninstall VDR Explorer.lnk.2.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\Common Files\VDR Explorer\unins000.exe
Source: VDR Explorer.lnk0.2.dr LNK file: ..\..\..\Program Files (x86)\Common Files\VDR Explorer\VDRExplorerAdminMode.exe
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Window found: window name: TMainForm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: VDR Explorer Setup.exe Static PE information: certificate valid
Source: VDR Explorer Setup.exe Static file information: File size 15923168 > 1048576
Source: VDR Explorer Setup.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\Jenkins\workspace\workspace\VDRExplorer_master\src\VDRExtraction\Release\VDRExtraction.pdb source: is-5OONJ.tmp.2.dr
Source: Binary string: C:\Jenkins\workspace\workspace\VDRExplorer_master\src\Libs\LiteZip\Release\LiteZip.pdb source: is-61L3J.tmp.2.dr
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavcodec\avcodec-58.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000059E7000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libswresample\swresample-3.pdb source: is-TENQ4.tmp.2.dr
Source: Binary string: C:\Jenkins\workspace\workspace\VDRExplorer_master\src\VDRExplorerAdminMode\Release\VDRExplorerAdminMode.pdbp source: is-V4VS3.tmp.2.dr
Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MT /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_CPUID_OBJ -DOPENSSL_BN_ASM_PART_WORDS -DOPENSSL_IA32_SSE2 -DOPENSSL_BN_ASM_MONT -DOPENSSL_BN_ASM_GF2m -DSHA1_ASM -DSHA256_ASM -DSHA512_ASM -DRC4_ASM -DMD5_ASM -DRMD160_ASM -DAESNI_ASM -DVPAES_ASM -DWHIRLPOOL_ASM -DGHASH_ASM -DECP_NISTZ256_ASM -DPOLY1305_ASM source: is-IG155.tmp.2.dr
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavutil\avutil-56.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000055B6000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ?crypto\stack\stack.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MT /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_CPUID_OBJ -DOPENSSL_BN_ASM_PART_WORDS -DOPENSSL_IA32_SSE2 -DOPENSSL_BN_ASM_MONT -DOPENSSL_BN_ASM_GF2m -DSHA1_ASM -DSHA256_ASM -DSHA512_ASM -DRC4_ASM -DMD5_ASM -DRMD160_ASM -DAESNI_ASM -DVPAES_ASM -DWHIRLPOOL_ASM -DGHASH_ASM -DECP_NISTZ256_ASM -DPOLY1305_ASMcrypto\ex_data.c source: is-IG155.tmp.2.dr
Source: Binary string: C:\Jenkins\workspace\workspace\VDRExplorer_master\src\VDRExplorerAdminMode\Release\VDRExplorerAdminMode.pdb source: is-V4VS3.tmp.2.dr
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavformat\avformat-58.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000057A9000.00000004.00001000.00020000.00000000.sdmp, is-64HQM.tmp.2.dr
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavfilter\avfilter-7.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.0000000005897000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\_proj\WinVDR\Packets\SDL\Src\VisualC\Win32\Release\SDL2.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000055B6000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libswscale\swscale-5.pdb source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000055B6000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavcodec\avcodec-58.pdb[ source: VDR Explorer Setup.tmp, 00000002.00000003.1752327019.00000000059E7000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\msys64\ffmpeg-4.4.1\libavdevice\avdevice-58.pdb source: is-LTTGC.tmp.2.dr
Source: Binary string: C:\Jenkins\workspace\workspace\VDRExplorer_master\src\Libs\mpglib.dll\Release\mpglib.pdb source: is-OJCQN.tmp.2.dr
Source: VDR Explorer Setup.exe Static PE information: section name: .didata
Source: VDR Explorer Setup.tmp.1.dr Static PE information: section name: .didata
Source: is-61L3J.tmp.2.dr Static PE information: section name: .00cfg
Source: is-99MG6.tmp.2.dr Static PE information: section name: _RDATA
Source: is-99MG6.tmp.2.dr Static PE information: section name: .00cfg
Source: is-LTTGC.tmp.2.dr Static PE information: section name: .00cfg
Source: is-O88NI.tmp.2.dr Static PE information: section name: _RDATA
Source: is-O88NI.tmp.2.dr Static PE information: section name: .00cfg
Source: is-64HQM.tmp.2.dr Static PE information: section name: .00cfg
Source: is-R3S6L.tmp.2.dr Static PE information: section name: .00cfg
Source: is-J0SVD.tmp.2.dr Static PE information: section name: .didata
Source: is-IG155.tmp.2.dr Static PE information: section name: _RDATA
Source: is-5LONE.tmp.2.dr Static PE information: section name: Shared
Source: is-TENQ4.tmp.2.dr Static PE information: section name: .00cfg
Source: is-NTAMP.tmp.2.dr Static PE information: section name: .00cfg
Source: is-5LONE.tmp.2.dr Static PE information: section name: .text entropy: 6.8255778200882515
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\swscale-5.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\VDRExplorer.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-EU8FP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\VDRExtraction.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-TENQ4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\gdiplus.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-OJCQN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\LiteZip.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-NTAMP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-J0SVD.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-LTTGC.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\avdevice-58.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\mpglib.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Users\user\AppData\Local\Temp\is-R7CVT.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe File created: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\avutil-56.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-64HQM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\VDRExplorerAdminMode.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-99MG6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\avfilter-7.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-IG155.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\swresample-3.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-V4VS3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\avcodec-58.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-2C7VK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-5LONE.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-5OONJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-61L3J.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-O88NI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\SDL2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\is-R3S6L.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\Program Files (x86)\Common Files\VDR Explorer\avformat-58.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VDR Explorer Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VDR Explorer\VDR Explorer.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VDR Explorer\VDR Explorer - No admin rights.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VDR Explorer\VDR Explorer - Safe mode.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VDR Explorer\Uninstall VDR Explorer.lnk Jump to behavior
Source: C:\Users\user\Desktop\VDR Explorer Setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\swscale-5.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\VDRExplorer.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-EU8FP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\VDRExtraction.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-TENQ4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\gdiplus.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-OJCQN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\LiteZip.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-NTAMP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-LTTGC.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\avdevice-58.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\mpglib.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-R7CVT.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\avutil-56.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-64HQM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\VDRExplorerAdminMode.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-99MG6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\avfilter-7.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\swresample-3.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-IG155.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-V4VS3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\avcodec-58.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-2C7VK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-5LONE.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-5OONJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-61L3J.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-O88NI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\SDL2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\avformat-58.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\VDR Explorer\is-R3S6L.tmp Jump to dropped file
Source: VDR Explorer Setup.tmp, 00000002.00000003.1759960011.00000000008A6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\uJ
Source: VDR Explorer Setup.tmp, 00000002.00000003.1759960011.00000000008A6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}t
Source: is-99MG6.tmp.2.dr Binary or memory string: VMware Screen Codec / VMware Video
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9K8UU.tmp\VDR Explorer Setup.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
No contacted IP infos