Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Resa Launcher Install.exe

Overview

General Information

Sample name:Resa Launcher Install.exe
Analysis ID:1449101
MD5:0f675d8a82d7e2d9198d1308bcfc2918
SHA1:c284c27bcee5f0b8b978451f7db76f61ca6748eb
SHA256:d78698c0ca1ed1aaae2c7fe878cc3d88133f0b7fa2a2430254a9ce44c3ba1949
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Compliance

Score:48
Range:0 - 100

Signatures

Modifies the windows firewall
Sigma detected: Files With System Process Name In Unsuspected Locations
Uses netsh to modify the Windows network and firewall settings
Checks for available system drives (often done to infect USB drives)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected TCP or UDP traffic on non-standard ports
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
Modifies existing windows services
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sigma detected: Suspicious Msiexec Execute Arbitrary DLL
Sigma detected: Use NTFS Short Name in Command Line
Uses 32bit PE files

Classification

  • System is w10x64_ra
  • Resa Launcher Install.exe (PID: 5160 cmdline: "C:\Users\user\Desktop\Resa Launcher Install.exe" MD5: 0F675D8A82D7E2D9198D1308BCFC2918)
    • resa launcher install.exe (PID: 2992 cmdline: ".\resa launcher install.exe" /m="C:\Users\user\Desktop\RESALA~1.EXE" /k="" MD5: E0F092BC83227D52E442F13BB3CDE076)
      • Crystal 8.5 for W11.exe (PID: 5632 cmdline: "C:\Users\user\AppData\Local\Temp\mia1\fb0\Crystal 8.5 for W11.exe" MD5: 5FF1538ECAA93249B16928FC93717B5F)
        • crystal 8.5 for w11.exe (PID: 6940 cmdline: ".\crystal 8.5 for w11.exe" /m="C:\Users\user\AppData\Local\Temp\mia1\fb0\Crystal 8.5 for W11.exe" /k="" MD5: A67A337BC7C5734284BC8362A9E98D96)
      • netsh.exe (PID: 5896 cmdline: netsh.exe advfirewall firewall delete rule name="RESA SMART - Resa Launcher" dir=in program="C:\ResaApps\ResaLauncher.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 3056 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 6464 cmdline: netsh.exe advfirewall firewall add rule name="RESA SMART - Resa Launcher" dir=in action=allow program="C:\ResaApps\ResaLauncher.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 6440 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 640 cmdline: netsh.exe advfirewall firewall delete rule name="RESA SMART - Pay Item" dir=in program="C:\ResaApps\Business_Services\PSmartEDM2016.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 796 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 3972 cmdline: netsh.exe advfirewall firewall add rule name="RESA SMART - Pay Item" dir=in action=allow program="C:\ResaApps\Business_Services\PSmartEDM2016.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 5152 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 6348 cmdline: netsh.exe advfirewall firewall delete rule name="RESA SMART - Pay Execute" dir=in program="C:\ResaApps\Business_Services\PSmartPayExecute.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 3412 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 1960 cmdline: netsh.exe advfirewall firewall add rule name="RESA SMART - Pay Execute" dir=in action=allow program="C:\ResaApps\Business_Services\PSmartPayExecute.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 3316 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 2496 cmdline: netsh.exe advfirewall firewall delete rule name="RESA SMART - Portal Security" dir=in program="C:\ResaApps\Security\PPortalSecurity.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 2300 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 2568 cmdline: netsh.exe advfirewall firewall add rule name="RESA SMART - Portal Security" dir=in action=allow program="C:\ResaApps\Security\PPortalSecurity.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 3592 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 880 cmdline: netsh.exe advfirewall firewall delete rule name="RESA SMART - GL Dist" dir=in program="C:\ResaApps\Business_Services\PSmartGLDist.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 1668 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 3660 cmdline: netsh.exe advfirewall firewall add rule name="RESA SMART - GL Dist" dir=in action=allow program="C:\ResaApps\Business_Services\PSmartGLDist.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 3740 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 7136 cmdline: netsh.exe advfirewall firewall delete rule name="RESA SMART - Polyplot" dir=in program="C:\ResaApps\PolySQL2012\PolySQL2012.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
      • netsh.exe (PID: 2840 cmdline: netsh.exe advfirewall firewall add rule name="RESA SMART - Polyplot" dir=in action=allow program="C:\ResaApps\PolySQL2012\PolySQL2012.exe" profile=domain,private,public remoteip=206.57.134.17 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 3544 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • MpCmdRun.exe (PID: 2496 cmdline: "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable MD5: B3676839B2EE96983F9ED735CD044159)
        • conhost.exe (PID: 2436 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • ResaLauncher.exe (PID: 880 cmdline: "C:\ResaApps\ResaLauncher.exe" MD5: 2C9822A0EA14B7168C3C452D5A63D8B2)
  • msiexec.exe (PID: 7000 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7060 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding E2E9E6F1A4A811C9F8F15AD92AE1CD0D MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 740 cmdline: C:\Windows\System32\MsiExec.exe -Embedding C18FBB39C7C886C04DDEAA7AB7F510F7 MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 3132 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding F207125D6A77848B38F0009DC23DCA58 E Global\MSI0000 MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 1252 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 8D29AC948328D58A797351E205CB6026 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7128 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding D3B57FF48BB51AE555ECBEB4FBA10E6E MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 7136 cmdline: "C:\Windows\syswow64\MsiExec.exe" /Y "C:\ResaApps\Business_Services\TaxControls\TaxControls.dll" MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • conhost.exe (PID: 5908 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • ResaLauncher.exe (PID: 3964 cmdline: "C:\ResaApps\ResaLauncher.exe" MD5: 2C9822A0EA14B7168C3C452D5A63D8B2)
  • cleanup
SourceRuleDescriptionAuthorStrings
C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exeJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
    C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exeJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
      C:\ProgramData\mia533A.tmp\resa launcher install.exeJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
        C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exeJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
          C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exeJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
            Click to see the 6 entries
            SourceRuleDescriptionAuthorStrings
            00000002.00000000.1192269828.0000000000401000.00000020.00000001.01000000.00000005.sdmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security

              System Summary

              barindex
              Source: File createdAuthor: Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Users\user\Desktop\Resa Launcher Install.exe, ProcessId: 5160, TargetFilename: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msiexec.exe
              Source: Process startedAuthor: frack113: Data: Command: "C:\Windows\syswow64\MsiExec.exe" /Y "C:\ResaApps\Business_Services\TaxControls\TaxControls.dll", CommandLine: "C:\Windows\syswow64\MsiExec.exe" /Y "C:\ResaApps\Business_Services\TaxControls\TaxControls.dll", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\msiexec.exe, NewProcessName: C:\Windows\SysWOW64\msiexec.exe, OriginalFileName: C:\Windows\SysWOW64\msiexec.exe, ParentCommandLine: C:\Windows\system32\msiexec.exe /V, ParentImage: C:\Windows\System32\msiexec.exe, ParentProcessId: 7000, ParentProcessName: msiexec.exe, ProcessCommandLine: "C:\Windows\syswow64\MsiExec.exe" /Y "C:\ResaApps\Business_Services\TaxControls\TaxControls.dll", ProcessId: 7136, ProcessName: msiexec.exe
              Source: Process startedAuthor: frack113, Nasreddine Bencherchali (Nextron Systems): Data: Command: ".\resa launcher install.exe" /m="C:\Users\user\Desktop\RESALA~1.EXE" /k="", CommandLine: ".\resa launcher install.exe" /m="C:\Users\user\Desktop\RESALA~1.EXE" /k="", CommandLine|base64offset|contains: r, Image: C:\ProgramData\mia533A.tmp\resa launcher install.exe, NewProcessName: C:\ProgramData\mia533A.tmp\resa launcher install.exe, OriginalFileName: C:\ProgramData\mia533A.tmp\resa launcher install.exe, ParentCommandLine: "C:\Users\user\Desktop\Resa Launcher Install.exe", ParentImage: C:\Users\user\Desktop\Resa Launcher Install.exe, ParentProcessId: 5160, ParentProcessName: Resa Launcher Install.exe, ProcessCommandLine: ".\resa launcher install.exe" /m="C:\Users\user\Desktop\RESALA~1.EXE" /k="", ProcessId: 2992, ProcessName: resa launcher install.exe
              No Snort rule has matched

              Click to jump to signature section

              Show All Signature Results

              Compliance

              barindex
              Source: Resa Launcher Install.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Include
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Include\sqlncli.h
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Lib
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Lib\x64
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Lib\x64\sqlncli11.lib
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Lib\x86
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Lib\x86\sqlncli11.lib
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\License Terms
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\License Terms\License_SQLNCLI_ENU.txt
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\KeyFile
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\KeyFile\1033
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\KeyFile\1033\sqlncli_keyfile.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Microsoft SQL Server\110\License Terms\License_SQLNCLI_ENU.txt
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\Microsoft SQL Server\110\License Terms\License_SQLNCLI_ENU.txt
              Source: Resa Launcher Install.exeStatic PE information: certificate valid
              Source: C:\Windows\System32\msiexec.exeFile opened: C:\Windows\SysWOW64\msvcr100.dll
              Source: C:\Windows\System32\msiexec.exeFile opened: z:
              Source: C:\Windows\System32\msiexec.exeFile opened: x:
              Source: C:\Windows\System32\msiexec.exeFile opened: v:
              Source: C:\Windows\System32\msiexec.exeFile opened: t:
              Source: C:\Windows\System32\msiexec.exeFile opened: r:
              Source: C:\Windows\System32\msiexec.exeFile opened: p:
              Source: C:\Windows\System32\msiexec.exeFile opened: n:
              Source: C:\Windows\System32\msiexec.exeFile opened: l:
              Source: C:\Windows\System32\msiexec.exeFile opened: j:
              Source: C:\Windows\System32\msiexec.exeFile opened: h:
              Source: C:\Windows\System32\msiexec.exeFile opened: f:
              Source: C:\Windows\System32\msiexec.exeFile opened: b:
              Source: C:\Windows\System32\msiexec.exeFile opened: y:
              Source: C:\Windows\System32\msiexec.exeFile opened: w:
              Source: C:\Windows\System32\msiexec.exeFile opened: u:
              Source: C:\Windows\System32\msiexec.exeFile opened: s:
              Source: C:\Windows\System32\msiexec.exeFile opened: q:
              Source: C:\Windows\System32\msiexec.exeFile opened: o:
              Source: C:\Windows\System32\msiexec.exeFile opened: m:
              Source: C:\Windows\System32\msiexec.exeFile opened: k:
              Source: C:\Windows\System32\msiexec.exeFile opened: i:
              Source: C:\Windows\System32\msiexec.exeFile opened: g:
              Source: C:\Windows\System32\msiexec.exeFile opened: e:
              Source: C:\Windows\System32\msiexec.exeFile opened: c:
              Source: C:\Windows\System32\msiexec.exeFile opened: a:
              Source: global trafficTCP traffic: 192.168.2.17:49720 -> 206.57.141.42:1433
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: global trafficDNS traffic detected: DNS query: portal.resa.net
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\649c0a.msi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9D24.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9DA2.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{D19A7273-0D14-44C3-95A2-2FBB862BA70E}
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9E20.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9E50.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9EBE.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\crpe32.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\exlate32.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\barcode.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\crxf_pdf.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\CRXF_RTF.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\Crxlat32.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2bact.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2bact3.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2bbde.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2bbtrv.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2bxbse.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2ctbtrv.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2iract.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2iract3.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2ixbse.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\P2ldb2.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\P2LIFMX.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2lodbc.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2lora7.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\P2lsql.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\P2lsyb10.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2molap.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sacl.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sdb2.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sexsr.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sfs.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sifmx.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2smapi.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2smcube.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2smsiis.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sNote.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2solap.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2soledb.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sora7.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2soutlk.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2srepl.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2ssql.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2ssyb10.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2strack.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2swblg.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2DAPP.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2DDISK.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2DMAPI.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2dnotes.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2dpost.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2dvim.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2FCR.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2fdif.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2FHTML.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2fodbc.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2frdef.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2frec.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2FRTF.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2FSEPV.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2FTEXT.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2fwks.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2FWORDW.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2FXLS.DLL
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2fxml.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2l2000.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2lbcode.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2lcom.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2ldts.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2lexch.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2lfinra.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2lsamp1.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u25dts.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u252000.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\649c0d.msi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\649c0d.msi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\649c0e.msi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBB9E.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBBFC.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBC1D.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{49D665A2-4C2A-476E-9AB8-FCC425F526FC}
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBC8B.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBCDA.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBD39.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\1033
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\1033\s11ch_sqlncli.chm
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\system32\1033
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\system32\1033\s11ch_sqlncli.chm
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\sqlncli11.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\system32\sqlncli11.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\1033\sqlnclir11.rll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\system32\1033\sqlnclir11.rll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\system32\msvcr100.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100\F_CENTRAL_msvcp100_x86.AFA96EB4_FA9F_335C_A7CB_36079407553D
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100\F_CENTRAL_msvcr100_x86.AFA96EB4_FA9F_335C_A7CB_36079407553D
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\649c11.msi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\649c11.msi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}\ARPIco
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC0F3.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC142.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\649c12.msi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC598.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC5E8.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{7F9E06BB-5B40-4E0F-91B1-6A37A71A3390}
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC617.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC638.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC658.tmp
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\649c15.msi
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\649c15.msi
              Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSI9D24.tmp
              Source: Resa Launcher Install.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
              Source: classification engineClassification label: mal52.evad.winEXE@60/217@1/4
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Microsoft SQL Server
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeFile created: C:\Users\user\AppData\Local\IIIQF
              Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:2436:120:WilError_03
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeFile created: C:\Users\user\AppData\Local\Temp\mia1
              Source: Yara matchFile source: 00000002.00000000.1192269828.0000000000401000.00000020.00000001.01000000.00000005.sdmp, type: MEMORY
              Source: Yara matchFile source: C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exe, type: DROPPED
              Source: Yara matchFile source: C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exe, type: DROPPED
              Source: Yara matchFile source: C:\ProgramData\mia533A.tmp\resa launcher install.exe, type: DROPPED
              Source: Yara matchFile source: C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exe, type: DROPPED
              Source: Yara matchFile source: C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exe, type: DROPPED
              Source: Yara matchFile source: C:\ProgramData\{34298CBE-CEDC-4FE1-85C1-841B00345C2F}\crystal 8.5 for w11.exe, type: DROPPED
              Source: Yara matchFile source: C:\ProgramData\mia533A.tmp\resa launcher install.exe, type: DROPPED
              Source: Yara matchFile source: C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exe, type: DROPPED
              Source: Yara matchFile source: C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exe, type: DROPPED
              Source: Yara matchFile source: C:\ProgramData\{34298CBE-CEDC-4FE1-85C1-841B00345C2F}\crystal 8.5 for w11.exe, type: DROPPED
              Source: Yara matchFile source: C:\ProgramData\mia533A.tmp\resa launcher install.exe, type: DROPPED
              Source: Resa Launcher Install.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ResaApps\ResaLauncher.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ResaApps\ResaLauncher.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ResaApps\ResaLauncher.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ResaApps\ResaLauncher.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeFile read: C:\Users\desktop.ini
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile read: C:\Users\user\Desktop\Resa Launcher Install.exe
              Source: unknownProcess created: C:\Users\user\Desktop\Resa Launcher Install.exe "C:\Users\user\Desktop\Resa Launcher Install.exe"
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeProcess created: C:\ProgramData\mia533A.tmp\resa launcher install.exe ".\resa launcher install.exe" /m="C:\Users\user\Desktop\RESALA~1.EXE" /k=""
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe "C:\Users\user\AppData\Local\Temp\mia1\fb0\Crystal 8.5 for W11.exe"
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeProcess created: C:\ProgramData\mia533A.tmp\resa launcher install.exe ".\resa launcher install.exe" /m="C:\Users\user\Desktop\RESALA~1.EXE" /k=""
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeProcess created: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe ".\crystal 8.5 for w11.exe" /m="C:\Users\user\AppData\Local\Temp\mia1\fb0\Crystal 8.5 for W11.exe" /k=""
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe "C:\Users\user\AppData\Local\Temp\mia1\fb0\Crystal 8.5 for W11.exe"
              Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding E2E9E6F1A4A811C9F8F15AD92AE1CD0D
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding C18FBB39C7C886C04DDEAA7AB7F510F7
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding F207125D6A77848B38F0009DC23DCA58 E Global\MSI0000
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 8D29AC948328D58A797351E205CB6026 E Global\MSI0000
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding D3B57FF48BB51AE555ECBEB4FBA10E6E
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\syswow64\MsiExec.exe" /Y "C:\ResaApps\Business_Services\TaxControls\TaxControls.dll"
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Resa Launcher" dir=in program="C:\ResaApps\ResaLauncher.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - Resa Launcher" dir=in action=allow program="C:\ResaApps\ResaLauncher.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Pay Item" dir=in program="C:\ResaApps\Business_Services\PSmartEDM2016.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - Pay Item" dir=in action=allow program="C:\ResaApps\Business_Services\PSmartEDM2016.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Pay Execute" dir=in program="C:\ResaApps\Business_Services\PSmartPayExecute.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - Pay Execute" dir=in action=allow program="C:\ResaApps\Business_Services\PSmartPayExecute.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Portal Security" dir=in program="C:\ResaApps\Security\PPortalSecurity.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - Portal Security" dir=in action=allow program="C:\ResaApps\Security\PPortalSecurity.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - GL Dist" dir=in program="C:\ResaApps\Business_Services\PSmartGLDist.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - GL Dist" dir=in action=allow program="C:\ResaApps\Business_Services\PSmartGLDist.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Polyplot" dir=in program="C:\ResaApps\PolySQL2012\PolySQL2012.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - Polyplot" dir=in action=allow program="C:\ResaApps\PolySQL2012\PolySQL2012.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Resa Launcher" dir=in program="C:\ResaApps\ResaLauncher.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - Resa Launcher" dir=in action=allow program="C:\ResaApps\ResaLauncher.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Pay Item" dir=in program="C:\ResaApps\Business_Services\PSmartEDM2016.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - Pay Item" dir=in action=allow program="C:\ResaApps\Business_Services\PSmartEDM2016.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Pay Execute" dir=in program="C:\ResaApps\Business_Services\PSmartPayExecute.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - Pay Execute" dir=in action=allow program="C:\ResaApps\Business_Services\PSmartPayExecute.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Portal Security" dir=in program="C:\ResaApps\Security\PPortalSecurity.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - Portal Security" dir=in action=allow program="C:\ResaApps\Security\PPortalSecurity.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - GL Dist" dir=in program="C:\ResaApps\Business_Services\PSmartGLDist.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - GL Dist" dir=in action=allow program="C:\ResaApps\Business_Services\PSmartGLDist.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\syswow64\MsiExec.exe" /Y "C:\ResaApps\Business_Services\TaxControls\TaxControls.dll"
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall add rule name="RESA SMART - Polyplot" dir=in action=allow program="C:\ResaApps\PolySQL2012\PolySQL2012.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeProcess created: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe ".\crystal 8.5 for w11.exe" /m="C:\Users\user\AppData\Local\Temp\mia1\fb0\Crystal 8.5 for W11.exe" /k=""
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding E2E9E6F1A4A811C9F8F15AD92AE1CD0D
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding C18FBB39C7C886C04DDEAA7AB7F510F7
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding F207125D6A77848B38F0009DC23DCA58 E Global\MSI0000
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 8D29AC948328D58A797351E205CB6026 E Global\MSI0000
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding D3B57FF48BB51AE555ECBEB4FBA10E6E
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\syswow64\MsiExec.exe" /Y "C:\ResaApps\Business_Services\TaxControls\TaxControls.dll"
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\ResaApps\ResaLauncher.exe "C:\ResaApps\ResaLauncher.exe"
              Source: unknownProcess created: C:\ResaApps\ResaLauncher.exe "C:\ResaApps\ResaLauncher.exe"
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: apphelp.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: aclayers.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: mpr.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: sfc.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: sfc_os.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: kernel.appcore.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: uxtheme.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: explorerframe.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: windows.storage.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: wldp.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: profapi.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: textinputframework.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: coreuicomponents.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: coremessaging.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: ntmarta.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: coremessaging.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: wintypes.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: wintypes.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: wintypes.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeSection loaded: textshaping.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: apphelp.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: aclayers.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: mpr.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: sfc.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: sfc_os.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: msimg32.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: version.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: winmm.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: msasn1.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: uxtheme.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: kernel.appcore.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: wtsapi32.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: winsta.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: olepro32.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: windows.storage.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: wldp.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: propsys.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: profapi.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: dwmapi.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: mscoree.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: srclient.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: spp.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: powrprof.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: vssapi.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: vsstrace.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: umpdc.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: textshaping.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: textinputframework.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: coreuicomponents.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: coremessaging.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: ntmarta.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: wintypes.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: wintypes.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: wintypes.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: msi.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: edputil.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: urlmon.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: iertutil.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: srvcli.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: netutils.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: windows.staterepositoryps.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: sspicli.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: appresolver.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: bcp47langs.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: slc.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: userenv.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: sppc.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: onecorecommonproxystub.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: onecoreuapcommonproxystub.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: apphelp.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: aclayers.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: mpr.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: sfc.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: sfc_os.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: kernel.appcore.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: uxtheme.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: explorerframe.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: windows.storage.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: wldp.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: profapi.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: textinputframework.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: coreuicomponents.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: coremessaging.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: ntmarta.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: wintypes.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: wintypes.dll
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeSection loaded: wintypes.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: srpapi.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: tsappcmp.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: netapi32.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: wkscli.dll
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeSection loaded: explorerframe.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: apphelp.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: aclayers.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: mpr.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: sfc.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: sfc_os.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: msimg32.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: version.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: winmm.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: msasn1.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: uxtheme.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: kernel.appcore.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: wtsapi32.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: winsta.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: olepro32.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: windows.storage.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: wldp.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: propsys.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: profapi.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: dwmapi.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: mscoree.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: srclient.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: spp.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: powrprof.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: vssapi.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: vsstrace.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: umpdc.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: textshaping.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: textinputframework.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: coreuicomponents.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: coremessaging.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: ntmarta.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: coremessaging.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: wintypes.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: wintypes.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: wintypes.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: msi.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: explorerframe.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: srpapi.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: tsappcmp.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: netapi32.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: wkscli.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: netutils.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: srvcli.dll
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeSection loaded: cscapi.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: msisip.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: version.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: linkinfo.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: ntshrui.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: srvcli.dll
              Source: C:\Windows\System32\msiexec.exeSection loaded: cscapi.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: mpclient.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: secur32.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: sspicli.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: version.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: msasn1.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: kernel.appcore.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: userenv.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: gpapi.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: wbemcomn.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: amsi.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: profapi.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: wscapi.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: urlmon.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: iertutil.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: srvcli.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: netutils.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: slc.dll
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: sppc.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: apphelp.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: aclayers.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: mpr.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: sfc.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: sfc_os.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: winmm.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: oleacc.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: version.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: oledlg.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: wsock32.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: uxtheme.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: kernel.appcore.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: wtsapi32.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: winsta.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: riched20.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: usp10.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: msls31.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: msdart.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: textshaping.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: textinputframework.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: coreuicomponents.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: coremessaging.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: ntmarta.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: wintypes.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: wintypes.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: wintypes.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: dpapi.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: comsvcs.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: sqlncli11.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: msvcr100.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: netapi32.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: netbios.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: cryptbase.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: secur32.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: sspicli.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: kerberos.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: msasn1.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: msv1_0.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: ntlmshared.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: cryptdll.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: ntdsapi.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: dsparse.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: logoncli.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: netutils.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: clusapi.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: dnsapi.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: iphlpapi.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: resutils.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: security.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: schannel.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: mswsock.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: rasadhlp.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: fwpuclnt.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: duser.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: xmllite.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: atlthunk.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: apphelp.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: aclayers.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: mpr.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: sfc.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: sfc_os.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: winmm.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: oleacc.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: version.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: oledlg.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: wsock32.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: uxtheme.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: kernel.appcore.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: wtsapi32.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: winsta.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: riched20.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: usp10.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: msls31.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: msdart.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: textshaping.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: textinputframework.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: coreuicomponents.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: coremessaging.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: ntmarta.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: wintypes.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: wintypes.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: wintypes.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: dpapi.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: comsvcs.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: sqlncli11.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: msvcr100.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: netapi32.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: netbios.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: cryptbase.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: secur32.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: sspicli.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: kerberos.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: msasn1.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: msv1_0.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: ntlmshared.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: cryptdll.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: ntdsapi.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: dsparse.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: logoncli.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: netutils.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: clusapi.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: dnsapi.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: iphlpapi.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: resutils.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: security.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: schannel.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: mswsock.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: rasadhlp.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: fwpuclnt.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: duser.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: xmllite.dll
              Source: C:\ResaApps\ResaLauncher.exeSection loaded: atlthunk.dll
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32
              Source: C:\ResaApps\ResaLauncher.exeFile written: C:\ResaApps\ResaLauncher.INI
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeWindow found: window name: TButton
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Include
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Include\sqlncli.h
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Lib
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Lib\x64
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Lib\x64\sqlncli11.lib
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Lib\x86
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\SDK\Lib\x86\sqlncli11.lib
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\License Terms
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\License Terms\License_SQLNCLI_ENU.txt
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\KeyFile
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\KeyFile\1033
              Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\Microsoft SQL Server\110\KeyFile\1033\sqlncli_keyfile.dll
              Source: Resa Launcher Install.exeStatic PE information: certificate valid
              Source: Resa Launcher Install.exeStatic file information: File size 19256760 > 1048576
              Source: C:\Windows\System32\msiexec.exeFile opened: C:\Windows\SysWOW64\msvcr100.dll
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\U2FTEXT.DLLJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\2C228EC0\DF9D80D2\p2iract.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\mia.libJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sexsr.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\7BFE20FE\DF9D80D2\U2FHTML.DLLJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\2750471D\DF9D80D2\p2smapi.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\D98EF2E2\DF9D80D2\u2frec.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msi.dllJump to dropped file
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeFile created: C:\Users\user\AppData\Local\Temp\mia2\mMSIExec.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\p2soledb.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\5D8AC0F0\91B5C31C\TaxControls.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBC1D.tmpJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msiinst.exeJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\1033\sqlnclir11.rllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\u2dnotes.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\P2lsyb10.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\OFFLINE\883718\F91E300C\exlate32.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\p2solap.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\78AE16CB\DF9D80D2\u2fdif.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\469BDAEB\DF9D80D2\U2FRTF.DLLJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\mWinRunExec.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exeJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2soutlk.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msiexec.exeJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\imagehlp.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\1033\sqlnclir11.rllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mFileBagIDE.dll\mFileBagEXE.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\AdvFirewallIDEPlugIn.dll\AdvFirewallEXEPlugIn.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\usp10.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\A601C89B\DF9D80D2\p2bbtrv.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\Microsoft SQL Server\110\KeyFile\1033\sqlncli_keyfile.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC142.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2srepl.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\u252000.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msimsg.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\14DD1572\DF9D80D2\p2ssyb10.dllJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeFile created: C:\Users\user\AppData\Local\Temp\mia1\mMSIExec.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msisip.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\p2sNote.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\u2lsamp1.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\Crxlat32.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2ssql.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC638.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sora7.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\riched20.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\A6F269F2\DF9D80D2\u2ldts.dllJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeFile created: C:\Users\user\AppData\Local\Temp\mia1\AdvFirewallEXEPlugIn.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\9182ED79\DF9D80D2\u2dvim.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\704854D2\DF9D80D2\p2bact3.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9D24.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100\F_CENTRAL_msvcr100_x86.AFA96EB4_FA9F_335C_A7CB_36079407553DJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sifmx.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\CRXF_RTF.DLLJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\unicode\update.exeJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\sqlncli11.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msihnd.dllJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeFile created: C:\Users\user\AppData\Local\IIIQF\7z.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\CC4A9AB7\DF9D80D2\p2sfs.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\P2ldb2.dllJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeFile created: C:\Users\user\AppData\Local\Temp\mia1\mWinRunExec.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\58D51985\DF9D80D2\u25dts.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msls31.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\4042563B\DF9D80D2\U2FWORDW.DLLJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\mspatcha.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\p2ixbse.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\E0F6211\DF9D80D2\p2molap.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcr100.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2DAPP.DLLJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2lcom.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2iract3.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\FBE04383\DF9D80D2\p2lodbc.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\u2lexch.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBBFC.tmpJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\resa launcher install.exeJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBB9E.tmpJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\B3D6BDF9\DF9D80D2\barcode.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2lora7.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\u2lfinra.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100\F_CENTRAL_msvcp100_x86.AFA96EB4_FA9F_335C_A7CB_36079407553DJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\OFFLINE\8B01F5B2\F91E300C\crpe32.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\P2LIFMX.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\A3E37DC2\DF9D80D2\p2smsiis.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\OFFLINE\mMSI.dll\mMSIExec.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\40A7F605\DF9D80D2\U2FXLS.DLLJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\crxf_pdf.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\9FBC96CE\DF9D80D2\U2DDISK.DLLJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\p2bxbse.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\shfolder.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\cabinet.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\E8FB99B2\DF9D80D2\u2fxml.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\1041948F\DF9D80D2\p2sacl.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC0F3.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2fodbc.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\p2swblg.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\31097DAF\DF9D80D2\u2fwks.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\ResaApps\CrystalFiles\u2lbcode.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2bbde.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2ctbtrv.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2dpost.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\sdbapi.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\70A680E\DF9D80D2\U2FSEPV.DLLJump to dropped file
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeFile created: C:\ProgramData\{34298CBE-CEDC-4FE1-85C1-841B00345C2F}\crystal 8.5 for w11.exeJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2l2000.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\E64120EF\DF9D80D2\U2FCR.DLLJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeFile created: C:\Users\user\AppData\Local\Temp\mia1\mFileBagEXE.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\8E3B9392\DF9D80D2\P2lsql.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\64572BA6\DF9D80D2\p2bact.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mMSI.dll\mMSIExec.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sdb2.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2frdef.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\13BF4A53\DF9D80D2\U2DMAPI.DLLJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\sqlncli11.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\607A9F5C\988B0B4D\ResaLauncher.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\598D777F\DF9D80D2\p2smcube.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\D7C8AF63\DF9D80D2\p2strack.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msihnd.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\CC4A9AB7\DF9D80D2\p2sfs.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\2C228EC0\DF9D80D2\p2iract.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\mia.libJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\58D51985\DF9D80D2\u25dts.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\7BFE20FE\DF9D80D2\U2FHTML.DLLJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\2750471D\DF9D80D2\p2smapi.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\D98EF2E2\DF9D80D2\u2frec.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msi.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msls31.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\4042563B\DF9D80D2\U2FWORDW.DLLJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\mspatcha.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\5D8AC0F0\91B5C31C\TaxControls.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\E0F6211\DF9D80D2\p2molap.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msiinst.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\FBE04383\DF9D80D2\p2lodbc.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\OFFLINE\883718\F91E300C\exlate32.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\resa launcher install.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\78AE16CB\DF9D80D2\u2fdif.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\B3D6BDF9\DF9D80D2\barcode.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\469BDAEB\DF9D80D2\U2FRTF.DLLJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\mWinRunExec.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\OFFLINE\8B01F5B2\F91E300C\crpe32.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msiexec.exeJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\A3E37DC2\DF9D80D2\p2smsiis.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\imagehlp.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\OFFLINE\mMSI.dll\mMSIExec.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mFileBagIDE.dll\mFileBagEXE.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\AdvFirewallIDEPlugIn.dll\AdvFirewallEXEPlugIn.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\usp10.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\40A7F605\DF9D80D2\U2FXLS.DLLJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\A601C89B\DF9D80D2\p2bbtrv.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\9FBC96CE\DF9D80D2\U2DDISK.DLLJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msimsg.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\shfolder.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\14DD1572\DF9D80D2\p2ssyb10.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\cabinet.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msisip.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\E8FB99B2\DF9D80D2\u2fxml.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\1041948F\DF9D80D2\p2sacl.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\31097DAF\DF9D80D2\u2fwks.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\riched20.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\A6F269F2\DF9D80D2\u2ldts.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\sdbapi.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\70A680E\DF9D80D2\U2FSEPV.DLLJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\9182ED79\DF9D80D2\u2dvim.dllJump to dropped file
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeFile created: C:\ProgramData\{34298CBE-CEDC-4FE1-85C1-841B00345C2F}\crystal 8.5 for w11.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\E64120EF\DF9D80D2\U2FCR.DLLJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\704854D2\DF9D80D2\p2bact3.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\8E3B9392\DF9D80D2\P2lsql.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\64572BA6\DF9D80D2\p2bact.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mMSI.dll\mMSIExec.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\unicode\update.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\13BF4A53\DF9D80D2\U2DMAPI.DLLJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\data\OFFLINE\607A9F5C\988B0B4D\ResaLauncher.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\598D777F\DF9D80D2\p2smcube.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeFile created: C:\ProgramData\mia7875.tmp\data\Default\D7C8AF63\DF9D80D2\p2strack.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\crxf_pdf.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sexsr.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC142.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2srepl.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBC1D.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcr100.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\1033\sqlnclir11.rllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\U2DAPP.DLLJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2lcom.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2iract3.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\Crxlat32.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC0F3.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2fodbc.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2ssql.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC638.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sora7.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2bbde.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2ctbtrv.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2dpost.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2l2000.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBBFC.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9D24.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBB9E.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2lora7.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100\F_CENTRAL_msvcr100_x86.AFA96EB4_FA9F_335C_A7CB_36079407553DJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100\F_CENTRAL_msvcp100_x86.AFA96EB4_FA9F_335C_A7CB_36079407553DJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sifmx.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2soutlk.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\p2sdb2.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Crystal\u2frdef.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\1033\sqlnclir11.rllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\sqlncli11.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\sqlncli11.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeFile created: C:\ProgramData\mia533A.tmp\mia.libJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\1033\sqlnclir11.rllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\1033\sqlnclir11.rllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100\F_CENTRAL_msvcp100_x86.AFA96EB4_FA9F_335C_A7CB_36079407553DJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100\F_CENTRAL_msvcr100_x86.AFA96EB4_FA9F_335C_A7CB_36079407553DJump to dropped file
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Microsoft SQL Server\110\License Terms\License_SQLNCLI_ENU.txt
              Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\Microsoft SQL Server\110\License Terms\License_SQLNCLI_ENU.txt
              Source: C:\Windows\System32\msiexec.exeRegistry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\SQLNCLI11.1
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\ResaApps\ResaLauncher.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
              Source: C:\ResaApps\ResaLauncher.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
              Source: C:\ResaApps\ResaLauncher.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
              Source: C:\ResaApps\ResaLauncher.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\U2FTEXT.DLLJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\2C228EC0\DF9D80D2\p2iract.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2sexsr.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\7BFE20FE\DF9D80D2\U2FHTML.DLLJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\2750471D\DF9D80D2\p2smapi.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\D98EF2E2\DF9D80D2\u2frec.dllJump to dropped file
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia2\mMSIExec.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\p2soledb.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\5D8AC0F0\91B5C31C\TaxControls.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIBC1D.tmpJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msiinst.exeJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\System32\1033\sqlnclir11.rllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\u2dnotes.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\P2lsyb10.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\OFFLINE\883718\F91E300C\exlate32.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\p2solap.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\78AE16CB\DF9D80D2\u2fdif.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\469BDAEB\DF9D80D2\U2FRTF.DLLJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\mWinRunExec.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exeJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2soutlk.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msiexec.exeJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\1033\sqlnclir11.rllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mFileBagIDE.dll\mFileBagEXE.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\AdvFirewallIDEPlugIn.dll\AdvFirewallEXEPlugIn.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\usp10.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\A601C89B\DF9D80D2\p2bbtrv.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\Microsoft SQL Server\110\KeyFile\1033\sqlncli_keyfile.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC142.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2srepl.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\u252000.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msimsg.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\14DD1572\DF9D80D2\p2ssyb10.dllJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia1\mMSIExec.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msisip.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\p2sNote.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\u2lsamp1.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\Crxlat32.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2ssql.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC638.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2sora7.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\riched20.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\A6F269F2\DF9D80D2\u2ldts.dllJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia1\AdvFirewallEXEPlugIn.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\9182ED79\DF9D80D2\u2dvim.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\704854D2\DF9D80D2\p2bact3.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI9D24.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100\F_CENTRAL_msvcr100_x86.AFA96EB4_FA9F_335C_A7CB_36079407553DJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\CRXF_RTF.DLLJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2sifmx.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\unicode\update.exeJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\sqlncli11.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msihnd.dllJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\IIIQF\7z.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\CC4A9AB7\DF9D80D2\p2sfs.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\P2ldb2.dllJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia1\mWinRunExec.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\58D51985\DF9D80D2\u25dts.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\msls31.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\4042563B\DF9D80D2\U2FWORDW.DLLJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\mspatcha.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\p2ixbse.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\E0F6211\DF9D80D2\p2molap.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\System32\msvcr100.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\U2DAPP.DLLJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\u2lcom.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2iract3.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\FBE04383\DF9D80D2\p2lodbc.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\u2lexch.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIBBFC.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIBB9E.tmpJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\B3D6BDF9\DF9D80D2\barcode.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2lora7.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\u2lfinra.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\2A566D94A2C4E674A98BCF4C525F62CF\11.0.2100\F_CENTRAL_msvcp100_x86.AFA96EB4_FA9F_335C_A7CB_36079407553DJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\OFFLINE\8B01F5B2\F91E300C\crpe32.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\P2LIFMX.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\A3E37DC2\DF9D80D2\p2smsiis.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\OFFLINE\mMSI.dll\mMSIExec.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\40A7F605\DF9D80D2\U2FXLS.DLLJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\crxf_pdf.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\9FBC96CE\DF9D80D2\U2DDISK.DLLJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\p2bxbse.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\shfolder.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\cabinet.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\E8FB99B2\DF9D80D2\u2fxml.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\1041948F\DF9D80D2\p2sacl.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC0F3.tmpJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\u2fodbc.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\p2swblg.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\31097DAF\DF9D80D2\u2fwks.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\ResaApps\CrystalFiles\u2lbcode.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2bbde.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2ctbtrv.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\u2dpost.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mWinRun.dll\ansi\sdbapi.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\70A680E\DF9D80D2\U2FSEPV.DLLJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\u2l2000.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\E64120EF\DF9D80D2\U2FCR.DLLJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia1\mFileBagEXE.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\8E3B9392\DF9D80D2\P2lsql.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\64572BA6\DF9D80D2\p2bact.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\mMSI.dll\mMSIExec.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\u2frdef.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Crystal\p2sdb2.dllJump to dropped file
              Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\System32\sqlncli11.dllJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\13BF4A53\DF9D80D2\U2DMAPI.DLLJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\598D777F\DF9D80D2\p2smcube.dllJump to dropped file
              Source: C:\Users\user\Desktop\Resa Launcher Install.exeDropped PE file which has not been started: C:\ProgramData\mia533A.tmp\data\OFFLINE\607A9F5C\988B0B4D\ResaLauncher.exeJump to dropped file
              Source: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exeDropped PE file which has not been started: C:\ProgramData\mia7875.tmp\data\Default\D7C8AF63\DF9D80D2\p2strack.dllJump to dropped file
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
              Source: C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
              Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformation
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe "C:\Users\user\AppData\Local\Temp\mia1\fb0\Crystal 8.5 for W11.exe"
              Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\syswow64\MsiExec.exe" /Y "C:\ResaApps\Business_Services\TaxControls\TaxControls.dll"
              Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
              Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
              Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
              Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation

              Lowering of HIPS / PFW / Operating System Security Settings

              barindex
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Resa Launcher" dir=in program="C:\ResaApps\ResaLauncher.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\ProgramData\mia533A.tmp\resa launcher install.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh.exe advfirewall firewall delete rule name="RESA SMART - Resa Launcher" dir=in program="C:\ResaApps\ResaLauncher.exe" profile=domain,private,public remoteip=206.57.134.17
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
              Source: C:\Program Files\Windows Defender\MpCmdRun.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire Infrastructure1
              Replication Through Removable Media
              1
              Windows Management Instrumentation
              1
              Windows Service
              1
              Windows Service
              33
              Masquerading
              OS Credential Dumping1
              Security Software Discovery
              Remote ServicesData from Local System1
              Non-Standard Port
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/Job1
              DLL Side-Loading
              11
              Process Injection
              2
              Disable or Modify Tools
              LSASS Memory1
              Process Discovery
              Remote Desktop ProtocolData from Removable Media1
              Non-Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
              DLL Side-Loading
              11
              Process Injection
              Security Account Manager11
              Peripheral Device Discovery
              SMB/Windows Admin SharesData from Network Shared Drive1
              Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
              DLL Side-Loading
              NTDS2
              System Owner/User Discovery
              Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
              File Deletion
              LSA Secrets2
              File and Directory Discovery
              SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials22
              System Information Discovery
              VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              No Antivirus matches
              SourceDetectionScannerLabelLink
              C:\ProgramData\mia533A.tmp\mia.lib0%ReversingLabs
              C:\Users\user\AppData\Local\IIIQF\7z.dll0%ReversingLabs
              C:\Users\user\AppData\Local\Temp\mia1\AdvFirewallEXEPlugIn.dll6%ReversingLabs
              C:\Users\user\AppData\Local\Temp\mia1\mFileBagEXE.dll0%ReversingLabs
              C:\Program Files\Microsoft SQL Server\110\KeyFile\1033\sqlncli_keyfile.dll0%ReversingLabs
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              portal.resa.net
              206.57.141.42
              truefalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                206.57.141.42
                portal.resa.netUnited States
                393581WAYNENETUSfalse
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1449101
                Start date and time:2024-05-29 18:29:33 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:58
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • EGA enabled
                Analysis Mode:stream
                Analysis stop reason:Timeout
                Sample name:Resa Launcher Install.exe
                Detection:MAL
                Classification:mal52.evad.winEXE@60/217@1/4
                Cookbook Comments:
                • Found application associated with file extension: .exe
                • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
                • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtOpenFile calls found.
                • Report size getting too big, too many NtOpenKeyEx calls found.
                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                • Report size getting too big, too many NtQueryAttributesFile calls found.
                • Report size getting too big, too many NtQueryValueKey calls found.
                • Report size getting too big, too many NtSetInformationFile calls found.
                • Report size getting too big, too many NtSetValueKey calls found.
                • Timeout during stream target processing, analysis might miss dynamic analysis data
                • VT rate limit hit for: Resa Launcher Install.exe
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):142198
                Entropy (8bit):4.8636486681530595
                Encrypted:false
                SSDEEP:
                MD5:0A641594A73B9B91228863C5B57FDE4E
                SHA1:DE9C9436D3399B88DFDCDAAD32A40B94347903B5
                SHA-256:80466A9E6BD1C71464FF12A91DF2E747B066FEB613105CCA5B25FBF313A7A005
                SHA-512:29B49CBB5790C27A3A8BA1D12E77A9E4C80F946D6DE8D7D6855B6E3019F41AB7D31821C66DE81870F8396A2D2EBE56B1F17B1476B80D09ECC2591241A3C0A71C
                Malicious:false
                Reputation:unknown
                Preview:...@IXOS.@.....@.c.X.@.....@.....@.....@.....@.....@......&.{D19A7273-0D14-44C3-95A2-2FBB862BA70E}..Crystal 8.5 for W11..crystal 8.5 for w11.msi.@.....@.....@.....@........\PROGRA~3\mia7875.tmp\&.{34298CBE-CEDC-4FE1-85C1-841B00345C2F}.....@.....@.....@.....@.......@.....@.....@.......@......Crystal 8.5 for W11......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{3ADD4FAA-1C8F-4DA8-BBBB-26CA4343830B}&.{D19A7273-0D14-44C3-95A2-2FBB862BA70E}.@......&.{FC238125-ED70-4322-B4B7-719B36409CE9}&.{D19A7273-0D14-44C3-95A2-2FBB862BA70E}.@......&.{2CFC096A-175E-45AD-99AC-D32E7946A853}&.{D19A7273-0D14-44C3-95A2-2FBB862BA70E}.@......&.{B4FAA560-15A4-4DE3-B326-1E5EEED915C4}&.{D19A7273-0D14-44C3-95A2-2FBB862BA70E}.@......&.{426DB683-838A-4493-BCE9-796514F8751D}&.{D19A7273-0D14-44C3-95A2-2FBB862BA70E}.@......&.{61218C32-63B7-44CC-9531-0DE156E43C49}&.{D19A7273-0D14-44C3-95A2-2FBB862BA70E}.@......&.{8770B2C3-5
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):146646
                Entropy (8bit):6.571268517542056
                Encrypted:false
                SSDEEP:
                MD5:FB91BB21C8C337CE7E25B8B5249045DA
                SHA1:5B5AB1F8A61F694D6961904FB9AF401CE8CE63EF
                SHA-256:73FDB64D30ABB5BB5D3CF082D88A90119C7FDF1E73C2D0DF2ADD41D22BCC178E
                SHA-512:C3B97700625E10B0E703DB04019629C0A5E8C7692803A7BB07C1EE38C28F82F401A93EFA0AC53BD55430B339C997D5EB022E910A265BA601167366D63731949E
                Malicious:false
                Reputation:unknown
                Preview:...@IXOS.@.....@.c.X.@.....@.....@.....@.....@.....@......&.{49D665A2-4C2A-476E-9AB8-FCC425F526FC}(.Microsoft SQL Server 2012 Native Client ..sqlncli.msi.@.....@4....@.....@......ARPIco..&.{B29CB6A0-B02A-4017-B7BF-746FA8C1356E}.....@.....@.....@.....@.......@.....@.....@.......@....(.Microsoft SQL Server 2012 Native Client ......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{6CC775C1-D2E1-48E0-9E02-37D5B0E9AE32}&.{49D665A2-4C2A-476E-9AB8-FCC425F526FC}.@......&.{005126C0-E9E4-4547-B3EB-BBB747D3031A}&.{49D665A2-4C2A-476E-9AB8-FCC425F526FC}.@......&.{932492BF-66A5-457A-988E-D16E8F282681}&.{49D665A2-4C2A-476E-9AB8-FCC425F526FC}.@......&.{95E62AEB-A564-422B-8C9E-1C9CE33F662A}&.{49D665A2-4C2A-476E-9AB8-FCC425F526FC}.@......&.{D0612BB3-AAC5-42B7-9DB4-FE2156769B39}&.{49D665A2-4C2A-476E-9AB8-FCC425F526FC}.@......&.{25AC4578-D179-47BF-BCD2-A29025D2EB79}&.{49D665A2-4C2A-476E-9AB8-FCC425F526FC}.@.....
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:modified
                Size (bytes):12635
                Entropy (8bit):5.348726300942578
                Encrypted:false
                SSDEEP:
                MD5:9DEFBFF985E97E496711E6C8F3DDFE36
                SHA1:BED5ACC1F8606732712CDC62563A746290DDB2D1
                SHA-256:2C76C0CD314EFE4FFA59668ABC3806E669C45AEB57CDA5E976E167A298B9F8A4
                SHA-512:009AE3C3CBDF423B25918AABC69800C4799C54647B5F2C89449C17270977A365A304A0EADC28FAFDB12CC8E93E81F17E022FED66C6F17DD4834A19592984A606
                Malicious:false
                Reputation:unknown
                Preview:...@IXOS.@.....@.c.X.@.....@.....@.....@.....@.....@......&.{7F9E06BB-5B40-4E0F-91B1-6A37A71A3390}..Resa Launcher Install..resa launcher install.msi.@.....@.....@.....@........\PROGRA~3\&.{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}.....@.....@.....@.....@.......@.....@.....@.......@......Resa Launcher Install......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{3B5C697E-2C37-4E32-A295-4682808D1B8C}&.{7F9E06BB-5B40-4E0F-91B1-6A37A71A3390}.@......&.{92253176-E0AD-4F8B-822B-694BA86F85EC}&.{7F9E06BB-5B40-4E0F-91B1-6A37A71A3390}.@......&.{BAE2307C-296B-4267-825C-1BF18A246DD3}&.{7F9E06BB-5B40-4E0F-91B1-6A37A71A3390}.@......&.{F3A84B07-45BD-4688-B32F-ED5295176E62}&.{7F9E06BB-5B40-4E0F-91B1-6A37A71A3390}.@......&.{9C5BE1D7-1412-4116-BA91-BD7C0F8A577F}&.{7F9E06BB-5B40-4E0F-91B1-6A37A71A3390}.@......&.{456F6F2B-636A-4FB9-AECE-8C05A3767ADB}&.{7F9E06BB-5B40-4E0F-91B1-6A37A71A3390}.@........RemoveODBC..Remov
                Process:C:\Windows\System32\msiexec.exe
                File Type:Unicode text, UTF-16, little-endian text, with very long lines (432), with CRLF line terminators
                Category:dropped
                Size (bytes):14310
                Entropy (8bit):3.480677973750327
                Encrypted:false
                SSDEEP:
                MD5:3666AB3B60D527211BA53203BEF9F911
                SHA1:F63F946EB36414C845B4FAA826379B5D84FD8F11
                SHA-256:9CFEC87CB1FE913126AA50811A09D34F494D9917B2958ED2B9056744AED26A35
                SHA-512:BB5C4515AE0FBF10094E638AC6DDD033A6C72398DED656E02448AAFF77E4C5C936A7584FD66B9838E66EDD5B85D0C7DE3DD456422C3A0A9348B87D2B24C47EED
                Malicious:false
                Reputation:unknown
                Preview:..M.I.C.R.O.S.O.F.T. .S.O.F.T.W.A.R.E. .L.I.C.E.N.S.E. .T.E.R.M.S.....M.I.C.R.O.S.O.F.T. .S.Q.L. .S.E.R.V.E.R. .2.0.1.2. .N.A.T.I.V.E. .C.L.I.E.N.T. .....T.h.e.s.e. .l.i.c.e.n.s.e. .t.e.r.m.s. .a.r.e. .a.n. .a.g.r.e.e.m.e.n.t. .b.e.t.w.e.e.n. .M.i.c.r.o.s.o.f.t. .C.o.r.p.o.r.a.t.i.o.n. .(.o.r. .b.a.s.e.d. .o.n. .w.h.e.r.e. .y.o.u. .l.i.v.e.,. .o.n.e. .o.f. .i.t.s. .a.f.f.i.l.i.a.t.e.s.). .a.n.d. .y.o.u... .P.l.e.a.s.e. .r.e.a.d. .t.h.e.m... .T.h.e.y. .a.p.p.l.y. .t.o. .t.h.e. .s.o.f.t.w.a.r.e. .n.a.m.e.d. .a.b.o.v.e.,. .w.h.i.c.h. .i.n.c.l.u.d.e.s. .t.h.e. .m.e.d.i.a. .o.n. .w.h.i.c.h. .y.o.u. .r.e.c.e.i.v.e.d. .i.t.,. .i.f. .a.n.y... .T.h.e. .t.e.r.m.s. .a.l.s.o. .a.p.p.l.y. .t.o. .a.n.y. .M.i.c.r.o.s.o.f.t....." ..u.p.d.a.t.e.s.,....." ..s.u.p.p.l.e.m.e.n.t.s.,....." ..I.n.t.e.r.n.e.t.-.b.a.s.e.d. .s.e.r.v.i.c.e.s.,. .a.n.d....." ..s.u.p.p.o.r.t. .s.e.r.v.i.c.e.s.....f.o.r. .t.h.i.s. .s.o.f.t.w.a.r.e.,. .u.n.l.e.s.s. .o.t.h.e.r. .t.e.r.m.s. .a.c.c.o.m.p.a.n.y. .t.h.o.s.e. .i.t.e.m.s.
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                Category:dropped
                Size (bytes):23640
                Entropy (8bit):6.774173737970971
                Encrypted:false
                SSDEEP:
                MD5:31411724D476CB74352C6E816613AD39
                SHA1:CA3619EA690D3892AF9636BD6A131D5542F34A0B
                SHA-256:118173020FB0BA4655FFB94ACD1A903D3BD5BBD0376FE3D2C916B6AC30D5586F
                SHA-512:BA70A869EB4BAC7E7EB0E1B5D98415EC7944CC879705078EF8F7140B8D0BC24087B334E7B1B180898D226B87085552B43E84759F61E199AF7F2FCF741A875C25
                Malicious:false
                Antivirus:
                • Antivirus: ReversingLabs, Detection: 0%
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......O.....@...@...@.......@.d.....@...A...@.d.....@.d.....@.......@.......@.......@.......@.......@.Rich..@.........................PE..d.....5O.........." ...........................7.............................`.......!....@.............................................4.......<....@.......0....... ..X<...P.......................................................................................text............................... ..`.data...X.... ......................@....pdata.......0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B........................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:C source, ASCII text, with very long lines (314), with CRLF line terminators
                Category:dropped
                Size (bytes):175473
                Entropy (8bit):5.36109654726284
                Encrypted:false
                SSDEEP:
                MD5:E18728306FF50E10128B78B1996C8FEC
                SHA1:B1213EBD3C35EBC9C364E06CA9DAA05A1F1A660A
                SHA-256:C456A690DB999E90100B20BA464BA06670310FC16959553CD6991FF411387B67
                SHA-512:8016B045CA325B2F05417A398E4ED0262BC5DC162377F2ADAA33DF02101F177BFA1AEEE08972B3B6FE01B475C5190F1D739E6942FF06C5E6296459FC7AB8596F
                Malicious:false
                Reputation:unknown
                Preview:..../* this ALWAYS GENERATED file contains the definitions for the interfaces */...... /* File created by MIDL compiler version 7.00.0555 */../* Compiler settings for sqlncli.idl:.. Oicf, W1, Zp8, env=Win32 (32b run), target_arch=X86 7.00.0555 .. protocol : dce , ms_ext, c_ext, robust.. error checks: allocation ref bounds_check enum stub_data .. VC __declspec() decoration level: .. __declspec(uuid()), __declspec(selectany), __declspec(novtable).. DECLSPEC_UUID(), MIDL_INTERFACE()..*/../* @@MIDL_FILE_HEADING( ) */....#pragma warning( disable: 4049 ) /* more than 64k source lines */....../* verify that the <rpcndr.h> version is high enough to compile this file*/..#ifndef __REQUIRED_RPCNDR_H_VERSION__..#define __REQUIRED_RPCNDR_H_VERSION__ 475..#endif..../* verify that the <rpcsal.h> version is high enough to compile this file*/..#ifndef __REQUIRED_RPCSAL_H_VERSION__..#define __REQUIRED_RPCSAL_H_VERSION__ 100..#endif....#include "rpc.h"..#include "rpcndr.h"..
                Process:C:\Windows\System32\msiexec.exe
                File Type:current ar archive
                Category:dropped
                Size (bytes):6164
                Entropy (8bit):5.036278857933051
                Encrypted:false
                SSDEEP:
                MD5:8AF8F618A6B6063D18EF5DD016B5A08B
                SHA1:1C95BA05A02294D0945B0D88B378100442AD7330
                SHA-256:AE6CEF1C8164775BEF8202C367E45C69F09B92B86D04876F45F7BEFC4196E4E8
                SHA-512:ABF4B25E3B071D1C8490C81181B7F7A4C341F41348C5230548CEDDD3749A70170877594C37FFB2185105E7352CCBA7CE3DC1B89EB71CEDA73534BC57A0E3EA9D
                Malicious:false
                Reputation:unknown
                Preview:!<arch>./ 1295647657 0 1066 `....5...........H...........D...D...........~...~...........P...P...........$...$...........................`...`...........(...(...P...P...l...l...........|...|...................................4...4................__IMPORT_DESCRIPTOR_sqlncli11.__NULL_IMPORT_DESCRIPTOR..sqlncli11_NULL_THUNK_DATA.OpenSqlFilestream.__imp_OpenSqlFilestream.__imp_dbprtypeA.dbprtypeA.__imp_bcp_batch.bcp_batch.__imp_bcp_bind.bcp_bind.__imp_bcp_colfmt.bcp_colfmt.__imp_bcp_collen.bcp_collen.__imp_bcp_colptr.bcp_colptr.__imp_bcp_columns.bcp_columns.__imp_bcp_control.bcp_control.__imp_bcp_done.bcp_done.__imp_bcp_initA.bcp_initA.__imp_bcp_exec.bcp_exec.__imp_bcp_moretext.bcp_moretext.__imp_bcp_sendrow.bcp_sendrow.__imp_bcp_readfmtA.bcp_readfmtA.__imp_bcp_writefmtA.bcp_writefmtA.__imp_dbprtypeW.dbprtypeW.__imp_bcp_initW.bcp_initW.__imp_bcp_readfmtW.bcp_readfmtW.__imp_bcp_writefmtW.bcp_writefmtW.__imp_bcp_getcolfmt.bcp_getcolfmt.__imp_bcp_setcolfm
                Process:C:\Windows\System32\msiexec.exe
                File Type:current ar archive
                Category:dropped
                Size (bytes):6592
                Entropy (8bit):5.080460585573793
                Encrypted:false
                SSDEEP:
                MD5:1FA6EE9C2E84B4A46127DF1AF4C09B7D
                SHA1:62FBF0018DE9BFFAB8E0EB4FE297F0A76B8A12F0
                SHA-256:FF52761730B58B81857DFE330BB240B90E948910025D92EB3369EAE3AF18F8FA
                SHA-512:0919E58FFD5DF98BC801044E03CCA67878924B45F2BEC0A20219DE08AFE969D591AF77FF678343D4889F62EC64C2B74C2F627BD4BE670FA0DF24CEDA9937F789
                Malicious:false
                Reputation:unknown
                Preview:!<arch>./ 1294708411 0 1240 `....5...:...l.......................n...n...........F...F..........."..."...................l...l...................l...l...........................T...T...........J...J...x...x...@...@..................."..."...&...&__IMPORT_DESCRIPTOR_sqlncli11.__NULL_IMPORT_DESCRIPTOR..sqlncli11_NULL_THUNK_DATA._OpenSqlFilestream@24.__imp__OpenSqlFilestream@24.__imp__dbprtypeA@4._dbprtypeA@4.__imp__bcp_batch@4._bcp_batch@4.__imp__bcp_bind@32._bcp_bind@32.__imp__bcp_colfmt@32._bcp_colfmt@32.__imp__bcp_collen@12._bcp_collen@12.__imp__bcp_colptr@12._bcp_colptr@12.__imp__bcp_columns@8._bcp_columns@8.__imp__bcp_control@12._bcp_control@12.__imp__bcp_done@4._bcp_done@4.__imp__bcp_initA@20._bcp_initA@20.__imp__bcp_exec@8._bcp_exec@8.__imp__bcp_moretext@12._bcp_moretext@12.__imp__bcp_sendrow@4._bcp_sendrow@4.__imp__bcp_readfmtA@8._bcp_readfmtA@8.__imp__bcp_writefmtA@8._bcp_writefmtA@8.__imp__dbprtypeW@4._dbprtypeW@4.__imp__bcp_initW@20._bcp_i
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):342096
                Entropy (8bit):6.531489968907709
                Encrypted:false
                SSDEEP:
                MD5:4930A47E0762174D96B47249F8913261
                SHA1:4FF9A34E738D9F74EA5EAAB09E38BA3F7759120F
                SHA-256:B3E5A5F4F0DEC5AFF7B8BDB824AD47F9204DAABC875BCF4E7344538243D474EA
                SHA-512:575FC7A72EB33E6319FA77031A19720AA372F5A9E8CCB167D8CABB9B4B7BFA5BFD94940E2C5664E566EAD01A3ECE3AE03BDAEE9BB646592453AB80A008C05483
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........f...5...5...5...5...5...5...5l..5...5...5...5..5...5...59..5..5...5l..5...5<..5...5l..5...5Rich...5........................PE..L......V...........!.....0..........Os.......@....V..........................0......................................0...................p...............P(......t7...................................................@..(............................text....(.......0.................. ..`.rdata...O...@...P...@..............@..@.data....a.......P..................@....rsrc...p...........................@..@.reloc...C.......P..................@..B........................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):10988624
                Entropy (8bit):6.967969669150402
                Encrypted:false
                SSDEEP:
                MD5:2C9822A0EA14B7168C3C452D5A63D8B2
                SHA1:560B8ACB7C51294C77596B8B3170B7BD520C7D0E
                SHA-256:9CCD2597F45F6DD200240A5074B6B1A2397987691CD119DBD8BD1A22DC64AB92
                SHA-512:FA7910326FE84BB33B64A39D852321EFC32E31B0CD7209A4E44277B878C228719410E040896E31EE83E33AE58B8C21476FB92BF86448537926D7B62C9F29273B
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....Z.e.................8^..HI.....PF^......P^...@.......................................@......@....................b......`b.n?...`j..4?.............P(....b..q............................b.....................,kb.......b......................text...(.].......^................. ..`.itext...7....^..8....^............. ..`.data...8N...P^..P...<^.............@....bss....0.....`..........................idata..n?...`b..@....`.............@....didata.......b.......`.............@....edata........b.......`.............@..@.tls....T.....b..........................rdata..].....b.......`.............@..@.reloc...q....b..r....`.............@..B.rsrc....4?..`j..4?..Ph.............@..@....................................@..@................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):909904
                Entropy (8bit):5.880021727255361
                Encrypted:false
                SSDEEP:
                MD5:6E3EDC2C03C4F97E76E23D0176603B8B
                SHA1:C22DBD78D235ED7167868EB656D75B55915CACAC
                SHA-256:D86DB5BC98423CDC10E690107C5881AFAFD1C60201076C3FDC140A18984C3485
                SHA-512:07AF368A97206FE170894B932DD628F195414D5D19180A2CEC7A15F918AA43259747FE71EEFE814D3861650DBBC301DF526D1355E0C7DFE6BC810904AD18B60D
                Malicious:false
                Yara Hits:
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exe, Author: Joe Security
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exe, Author: Joe Security
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\mia533A.tmp\data\OFFLINE\851024AE\356DA8CB\ResaScannerHelper.exe, Author: Joe Security
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@..............................................@...........................@..R"......................P(.......{..................................................................................CODE....,........................... ..`DATA................................@...BSS.....m....0...........................idata..R"...@...$..................@....tls.........p.......B...................rdata...............B..............@..P.reloc...{.......|...D..............@..P.rsrc...............................@..P....................................@..P........................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):419920
                Entropy (8bit):6.612991988444453
                Encrypted:false
                SSDEEP:
                MD5:BB2115B84D3B56A8600307C9F2C756D5
                SHA1:AB4AE5A01EC3191046D0E926D048BE35FF3F3497
                SHA-256:6D7138F42D5FD95DB212825DA4845739260669A5BF51CB618B5E5B665F2E0A3E
                SHA-512:BEC53A2DCB1D20937447B3129C940B8048307F6A51BD3981321FC9D0B917C690ACD410DC6462374A0173167D969804092994A3B8AB732EFA62D158FA3783F829
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....X.................`..........$w............@.................................................................. ..Z........$.......>...........@..P(...0...X...................................................................................text....V.......X.................. ..`.itext.......p.......\.............. ..`.data................d..............@....bss.....L...............................idata...$.......&..................@....edata..Z.... ......................@..@.reloc...X...0...Z..................@..B.rsrc....>.......>..................@..@.....................@..............@..@........................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):1873488
                Entropy (8bit):6.7046738193733715
                Encrypted:false
                SSDEEP:
                MD5:6BBA9873D80027DCF5EA8F3B1F6F56B9
                SHA1:7140A4941B706426A85F3DB54A4F8FB3E9879620
                SHA-256:0DAA8F536125A7ECAC12009C7F613BC7F0E4881B527549FDA27E5D6242EBC0EE
                SHA-512:70C5480750323EC4F5989771A198094C8B09B8E90FD822FA56FB5008F0A2B141FB313F80C47AE0ECD305CAD3FBDBB4E4F280C34FB49CE822917B208EE31EC8F9
                Malicious:false
                Yara Hits:
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exe, Author: Joe Security
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exe, Author: Joe Security
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\mia533A.tmp\data\OFFLINE\F82E73DF\548C85B\ResaReportView.exe, Author: Joe Security
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.....................r......(.............@.................................S3...........@...........................p...&... ...............n..P(......4R..................................................................................CODE................................ ..`DATA....<<.......>..................@...BSS..........P.......:...................idata...&...p...(...:..............@....tls.................b...................rdata...............b..............@..P.reloc..4R.......T...d..............@..P.rsrc........ ......................@..P.....................n..............@..P........................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):5923400
                Entropy (8bit):7.970717861583875
                Encrypted:false
                SSDEEP:
                MD5:5FF1538ECAA93249B16928FC93717B5F
                SHA1:D4DC2715D2B6E1BDBCFEA99AB635B4CA296E4A78
                SHA-256:D489422234418E7357F54CE90D44768D6D2E087D24C46898CEBD4530FB61A38A
                SHA-512:935DF438B28A8EB9FCFDF6AED1124BD7AAFB1E7020BB0D0CCB2E2E31B867AF5DE956F1DE2A041A07690B04DE53CED269BA3F70D4A01B640A0059438CC90D935C
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........ew...........|.....|.....|.......t.....b...........|......V.....|.....Rich............................PE..L...km.b..........#..........d......X,....... ....@..................................Z.............................................P...............9Z.P(...........................................R..@............ ...............................text............................... ..`.rdata...... ......................@..@.data............$..................@....rsrc........P......................@..@........................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Microsoft SQL Server 2012 Native Client , Author: Microsoft Corporation, Keywords: Installer, Comments: Microsoft Microsoft SQL Server 2012 Native Client MSI, Template: x64;1033, Revision Number: {B29CB6A0-B02A-4017-B7BF-746FA8C1356E}, Create Time/Date: Sun Feb 12 03:07:12 2012, Last Saved Time/Date: Sun Feb 12 03:07:12 2012, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML v0.0.0.0, Security: 2
                Category:dropped
                Size (bytes):12058624
                Entropy (8bit):6.664072696123251
                Encrypted:false
                SSDEEP:
                MD5:EAE8E28F2630FD3061938C5984397773
                SHA1:06B5E990F69F90D019988BA4D1220EEA63818702
                SHA-256:94B3018E28A00EF53FAF55D38C44B568E4D4950C6D4AB01C3E77DCF0798C928E
                SHA-512:1B49D6E060EE4E99205FC394914B6BBFB20CB7792AAE8BFBB3D0CC44644A95132495068E0D09A81B73CBA72013D8C0AE26DF7DA2CB91AB19CEE4063537F4C753
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):1466448
                Entropy (8bit):6.6445976302452685
                Encrypted:false
                SSDEEP:
                MD5:A2F168B2375896E0C0C7371E559D5137
                SHA1:F7E1F75D1A92D908E215F6654F3B5DBDB1E083A6
                SHA-256:C525EE68993D7BDF87C8B6ED6B9CCD0173E94A5FFB5F7094306018746E97C671
                SHA-512:6FEC78A3674A204FBA55B0B818D10EBCA62B9F488AABB25177AC270A94220C83A2D4C277DC1E3EB94BB144112496D82E6F0FCF0214ADD24BED8FCDE5642EA05D
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....T:b.................t..........(..............Q....................................................................R....`..*6.......`...........8..P(...........................................................j..`.......^....................text...@].......^.................. ..`.itext.......p.......b.............. ..`.data...$i.......j...x..............@....bss.... T...............................idata..*6...`...8..................@....didata.^...........................@....edata..R............$..............@..@.rdata...............&..............@..@.reloc...............(..............@..B.rsrc....`.......`..................@..@.....................8..............@..@........................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):1390160
                Entropy (8bit):6.681533416319385
                Encrypted:false
                SSDEEP:
                MD5:37FA77C5BBF7BE0364054ED3E8895841
                SHA1:E9C9837DEF64146B88643FA305F477FCE9EB67BE
                SHA-256:C23FFDC1B01F8454E2E0B20A6696A8AF9A0F19ABFC6317FFB6292B139C12C560
                SHA-512:B782E582B23EE68190756FE7FAD978F389A83DF4465B70D0A4D408F58938554331F3ADE9B0B9E12997B7571F9B3BA9F68BA534C9B0EB27F90470883D7B8048B9
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...uT:b.................~.........................Q................................=...................................O....P..@=...`...Z..............P(..........................................................d[..\............................text....i.......j.................. ..`.itext...............n.............. ..`.data....O.......P..................@....bss....(T...............................idata..@=...P...>..................@....didata.............................@....edata..O...........................@..@.rdata..............................@..@.reloc..............................@..B.rsrc....Z...`...Z..................@..@....................................@..@........................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
                Category:dropped
                Size (bytes):66400
                Entropy (8bit):6.799982794198286
                Encrypted:false
                SSDEEP:
                MD5:35D7EA046FA4E638133CD477E125D0F6
                SHA1:829D59CAA0A20A6419B7A7E07940FD2082B9C6E1
                SHA-256:0FF9CA84D6B5AF01DF7E729AFDF11B66000BA861CEEB81814DC1CF7D7192A027
                SHA-512:685E27F608B8ADF8B2CDC0E2EB85D07A7AEC0BCF69CEE1016A4762457D243B2381AB69CC0806F9D5366B848BC96E07E548BD9B847D4B60FE22EBFE48349A91BC
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........{J...$...$...$...%...$..97...$..."...$...$...$.Rich..$.................PE..L...R.C8...........#.........2.....................u.........................0.......:..........................................<.......................P(... ......`.......................................`...D.......\............................text...M........................... ..`.data....(..........................@....rsrc...............................@..@.reloc....... ......................@..B4.D8 ...0[.8-...5.D87...........KERNEL32.dll.NTDLL.DLL.ole32.dll........................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):116336
                Entropy (8bit):6.439787262709117
                Encrypted:false
                SSDEEP:
                MD5:34D20BE07E49004FDB6D0F933DB29ADA
                SHA1:90622236DEB5E114C08EC3C083C6FEE2FD3592DE
                SHA-256:059663DA17F7076A3DD6029690A6B47399CA0D59EB570300FED769A35CAAB161
                SHA-512:47762B4711714CF50F0D4587423DB1781E52671DE6386F85D90805F9F9DF3E54DA4AF3A5957FA4C80EBBB51CF6B606851E5198A0463092902B6FC07E25909ECA
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....B/3...........!.....P...P.......S.......`.....v.................................n...............................p.......k..(................... ...P(...........`...............................................`...............................text....N.......P.......... ....... ..`.rdata.......`.......`..............@..@.data...4............x..............@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Windows Installer database, Author: Microsoft Corporation, Keywords: Installer,MSI,Database, Comments: Instala Windows Installer, Create Time/Date: Wed Apr 14 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 2, Template: Alpha,Intel;1033, Last Saved By: Alpha,Intel;3082, Revision Number: {CA04376B-A6BA-F246-20B1-EBD703D8F0D2}1.0.00.000;{CA04376B-A6BA-F246-20B1-EBD703D8F0D2}1.0.00.000, Number of Pages: 30, Number of Characters: 8
                Category:dropped
                Size (bytes):963584
                Entropy (8bit):6.053817169543458
                Encrypted:false
                SSDEEP:
                MD5:B7B0A6F4FB28CCB9533C108CAB9A6329
                SHA1:2C1B269C8D696BC2C9B175CFE6DC9E89F6D61B8E
                SHA-256:5030B553AA238BD7850EC5DC9E23871B93737FACDE7A4FF891302B7C1D0AF4EC
                SHA-512:814FE5201B8551964A7C97EB63CF6B18BA113EEB72D94EC9108602B93CFC674875509EA568FD973E70142C26AD09F530054917AC37BB67CD4F8C2158AFD5D435
                Malicious:false
                Reputation:unknown
                Preview:......................>.......................................................p.......j.......n.......v.......t.......k.......g.......................................................................................................................................................................................................................................................................................................................................................................................................................C.......................................................A.......D................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...i.......E...f...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e.......g...h...l...j...k.......m...n...o...........r...s...t...u...v...w...x...y...z...
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):1938000
                Entropy (8bit):6.142889979188445
                Encrypted:false
                SSDEEP:
                MD5:20C60F3B2B5A6F00182653A5EB0A53D7
                SHA1:0E3125F4B165B4B62F92A79DCF761A0C998F0129
                SHA-256:76626657D8629874CDAD8A0CAF6197F2BD689326F870B7C2ED5E23D5A39E60F9
                SHA-512:24DB644E27872D357D2BC92F218F17BFD0BD7CEBA6382F61FA12BB82CDA2711EA83C1F405A6868DEEF18C9EA1E976EDB9E779373C95B2AE4E1C16E7EC39AAF4B
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Y...8..8..8....c.8..I.U.8..z.f.8..8~..9..z.?.8..z.@.8..Z.b.8..Z.c..8....:.8..z.B.8..Rich.8..........PE..L......;...........!.........z.......i.......0....@.................................-...........................................x.......0)...........j..P(...........................................................................................text............................... ..`.orpc........ ...................... ..`.data....|...0...d..................@....rsrc...0).......*...n..............@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):93776
                Entropy (8bit):6.562677869433461
                Encrypted:false
                SSDEEP:
                MD5:1D6102A0045231A5EEFC250F265F8803
                SHA1:D0544EC7E82A541E0C226CC3EB09E27E6A2BBF91
                SHA-256:6DAF8A3AE68E70CBC149CB7A770BD018DD888BCFEC78C407C0D82A9F241EF20F
                SHA-512:3E8CEFDF20EAFE4553BCDA394EE57CECEEC01F64E42655EA12A0A076ECF2ADD716AB0F33FFD5C3E78C35C8DC7C1A971BD047C7F485C76C536A5AC08FDAB80E11
                Malicious:true
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......P2...S...S...S...p...S...S...S...p..S...p..XS...p..S...p...S...p...S..Rich.S..........................PE..L......;.....................P............... ..................................................................................x....`..X............F..P(..............................................................|............................text............................... ..`.data...T3... ... ..................@....rsrc...X....`.......*..............@..@................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):307792
                Entropy (8bit):6.376592471429444
                Encrypted:false
                SSDEEP:
                MD5:204CA141987FF6CC3967F250D8E536C4
                SHA1:65104FEFC8E26D57AECAB27DF207C0BD736AB2BE
                SHA-256:B7084298565F974E18664B53F0BE9A67D47BB59E3567DE23575B886404823D9B
                SHA-512:4D3B7CCA6355DCAF2EEA2DC679806A0FF260C2E85F43D5A5676201559CEA4A4716E20205FF1AE290F93BEBCD74479A2D9647A819878D0680D078BEB61D9B46E9
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........E-.Q$C,Q$C,Q$C,..Z,^$C,Q$B,.$C,...,G$C,..|,P$C,...,P$C,..^,^$C,.._,/$C,..~,P$C,RichQ$C,........................PE..L.....;...........!..............................@.....................................................................................................P(.......+......................................................\............................text...c........................... ..`.data....4..........................@....rsrc...............................@..@.reloc...5.......6...T..............@..B................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):47184
                Entropy (8bit):6.644006575142804
                Encrypted:false
                SSDEEP:
                MD5:2A92B1F59F4617C0707A282D01034BD7
                SHA1:8D23835646E564DAC2B0EA36E4DA6246837F978E
                SHA-256:FFAC0701CE8470A3D794A34C313C38AD9973673B960C71C24DAACF8CB180089C
                SHA-512:D624DAC5A2152733F7B06DF0BE10C3CE8BCC38274BB0FEE5944DF6BD42536C9BE40AA740641C2E705B19E4D13E49C32807543F6401AA5BAFE85DF3F489278B74
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......6.jir..:r..:r..:...:y..:r..:...:..D:|..:...:I..:..A:s..:...:u..:..9:s..:Richr..:................PE..L.....;.................|...........I......................................................................................$...x.......................P(...........................................................................................text...$z.......|.................. ..`.data...x...........................@....rsrc...............................@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:Windows application compatibility Shim DataBase
                Category:dropped
                Size (bytes):134164
                Entropy (8bit):5.119567377291569
                Encrypted:false
                SSDEEP:
                MD5:9A7CA59803DD20AC5C6B900E8665169B
                SHA1:247C0DC1C82F70E6E7F9CAFA9F7C8C69EC4C2648
                SHA-256:AEEC814144D4253D3167360EC6399F542D9123E4D5878808BAC279D6436B3C8D
                SHA-512:DADD8F6023F063F59C0F7703D706218F59F8D54EDFF3CB2CF8C71C67DF22CF6EE32C379DD65C2C69D3FFCF0D84C500737EA294C9CB1126656FB1D6E629F3058C
                Malicious:false
                Reputation:unknown
                Preview:....A*..sdbf.xh....x.....8.p.8.`.@......x...VILEBODAf...02MOCUED~...OCHCNERF....OCOTOHPI....RT1002IP....IERUTCIP....VEZILAER....DACOBRUT......YAWNIW&...IUSSKROW>....x.....8.p.8.........F1R..'.r....*c..........n...@............N...p{...4!....k.\o8a.&.........>.+......)...w/........=@i?........=@i?.........ED....q-...I.....qM...I.....q]...I:....q}...I.....g.tWc.L.......s3.`O4......~.'.Xl...Y0.50..YV.......3.i\.....7..AZd.f...K@}...F.....0i........?.3i....2...,.3.....j.....*...........\...6.l.....\...6.......Q. .d......8 ?..H...,....@N.........i*%.B...P...>.......X6...........^^..^!......^^..^!.T....^^..^!.D....^^..^!.6.......L........x.....8.p.8...@...........p..-1..V...U.h.........u.......D.....8.........."a..N..D....H.`T.z........../'2...t=.'.o.+........M..0........9.W1j.......|.GE....qO.2-:.H:...,....I.R....T.kI..SYF...;.Ek..Y......;..nw[d....8..O.f......'.fK.h4...c...I..q....J....z.y....n..g...|......!Y|p.......&Eo....r.......L........eS.....B...&.w........vI!$!E-.H.
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):858192
                Entropy (8bit):5.8182312683176045
                Encrypted:false
                SSDEEP:
                MD5:C7C8AA0F7CF5C185EA61AF2FFD33BA39
                SHA1:C8A8016AC7AF9D1B56C6A539BE1828BD65B58BC2
                SHA-256:F21C89C36BA55089213FACAB62E12F16DC320F8224F92E303963F62440412D73
                SHA-512:5419FBB4DB6ED3778681E15C835FF3593794D37CF56A564717F7BA4119065C40C252AAFBFDCA9D8208B35F26FD9BFB641F4C9564C7046F703A4A0825E5F805A3
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........=.C.S.C.S.C.S.....B.S...n.B.S.RichC.S.................PE..L...U..;...........!.................................................................Y..................................................x...............P(...........................................................................................rsrc...x...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):50768
                Entropy (8bit):6.575362234666433
                Encrypted:false
                SSDEEP:
                MD5:70BC9CAA114336358338F5D78FB57128
                SHA1:EFEEF34A4B4B43440AF0E2D620ED0B187B93B69E
                SHA-256:5C63A78D77E9439FFAB8BC6805A1AFE49B6EF60979C3BD40F69CEB2DB21AEF7E
                SHA-512:0DB683D93148DB68D8238A7A798B0123037A93DCBDD295B66E13825A00C38AC2F4790045E5818B92E9109A089BA9FC86B8BE27DC6908893E283500258120218E
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........k.c.8.c.8.c.88@.8.c.8.@.8.c.88@.8.c.8.c.8.c.88@.8.c.8U@.8.c.8.@.8.c.88@.8.c.8Rich.c.8........................PE..L......;...........!.....|...&......Y<............@..................................`.............................. ...8......(.......................P(..........0................................................................................text...X{.......|.................. ..`.data...|...........................@....rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
                Category:dropped
                Size (bytes):178256
                Entropy (8bit):6.159636816456151
                Encrypted:false
                SSDEEP:
                MD5:58BB2FB4EEA00C0C2F3C327BA4E0E515
                SHA1:EC4AB3056320A1F3457216F08A26F2D322186ECF
                SHA-256:F724D066B383C18336B2C154554C41FD77C4724FD239EDA78A1E662EAF97528E
                SHA-512:E0517EB0E0C423503C4241694A0581C66C6600838E901477DC714FB6A1B82B41FB13A9BCAEA674E2FFCE732268CFC8C98A98D697115FCA588871DD716A769027
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........#..cp..cp..cph.ip..cp8.ep..cph.gp..cpRich..cp........................PE..L......6...........#.....0...@............... .....H.................................Q...............................A..Y............`..................P(...p.......J...............................................................................text....#.......0... .............. ..`.rdata.......@.......P..............@..@.data...@....P.......`..............@....rsrc........`.......p..............@..@.reloc.......p......................@..B................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):39072
                Entropy (8bit):7.037261481263887
                Encrypted:false
                SSDEEP:
                MD5:EB106508B42FBDB53D36799FC6626901
                SHA1:D7EAC30FD038A668E939D248C844A648BDC25C77
                SHA-256:A97AFEE24AC381D0C53297EE032DC0CE8BFB3B2AA04B36C395D8E682DDBE2CFA
                SHA-512:F04491724A75DA88029BAAE7075A7468D3FBE8587DE3A6F1D61076BCECA8D241644785C1F5D51B0EAC756DEC50A7CDD479922059C05921167755C30574D3DDAC
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$................................................Rich...........................PE..L....aJ9...........!.....d.........................X..............a.................SB...............................p.......n..(...................Pp..P(......X...`...................................................T............................text....b.......d.................. ..`.rsrc................j..............@..@.reloc...............n..............@..B................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):441456
                Entropy (8bit):6.702009266718369
                Encrypted:false
                SSDEEP:
                MD5:753B4B437434AD5B91FB9B10B9992DC9
                SHA1:18991AA65B3183D40392C08F7D1CA18CEC13643D
                SHA-256:03B72EDA1D30CA1281B0685BB2CCDBDE9F316E0268D51D958CFB74334666F0EF
                SHA-512:3C0C212F7744A152339AB7155A6884E4FD3A59AAF8DD32C19D28AC7B641C69918CC9CD00389BD27772C8077DC19BF0C2CD3027A5DBED48AAB1AB92BB850C1FAA
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......1.Gu...u...u...u...{...,......._...t...u...$...Richu...........PE..L...0.V8...........!...............................H...............................................................`...=................w.......... ...P(.......(..<.......................................X...l...............`....................text............................... ..`.data...............................@....rsrc....w.......x..................@..@.reloc...(.......*...j..............@..B4.D80...0[.8=...4.D8G...4.D8T.....+8_...........KERNEL32.DLL.NTDLL.DLL.ADVAPI32.DLL.USER32.DLL.GDI32.DLL........................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):73808
                Entropy (8bit):6.913887220720017
                Encrypted:false
                SSDEEP:
                MD5:CBA768B488959FDAAD6E1F3AC3D78EC0
                SHA1:E1DA78D26B541B39EABD8106542D6983FB9BFB5A
                SHA-256:D78D1CF27BDADDD7ED0F5074EB05A8CA6C1ADD4F56E0D7F3BE37EA7197C5C070
                SHA-512:99142AA7B759CD00B6388BA9AFE33AC73006ABC2C264D2FB2A6075EF98CAC875D1C1BC2D28AC9478CCBE2C55DB9711CAFB687ADDC87B89BDB7B554B96FFDD157
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......N..O.h...h...h...K...h...h..Nh...K...h...K...h...K...h...K...h...K...h..Rich.h..........PE..L....};...........!...............................G......................... .....................................P...c.......P.......................P(..................................................p...X....................................text............................... ..`.data...............................@....rsrc...............................@..@.reloc..............................@..B..};(.....};3.....};@.....};M...........msvcrt.dll.ADVAPI32.dll.KERNEL32.dll.NTDLL.DLL..................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):31344
                Entropy (8bit):6.131370538584937
                Encrypted:false
                SSDEEP:
                MD5:A5AB6F221350B1FE49986E936DED231F
                SHA1:FC59D38F0525488374CDD329669CDE8A937F413F
                SHA-256:7A32C533613C8341E97CADCE40B250614B83299565344A47A9CAED6E7F44A748
                SHA-512:B813E005E6415EF01241FCDFB75656A485A5E18E8A760D1D756A7ED85E14EA7F46AAF85F9A772C73591B70EA4FFF86E2DDEEAFAA84570143EAC6F6A87DCD9D9E
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Q{J...$...$...$...%.'.$.L97...$..."...$...$...$.Rich..$.................PE..L...q.^7...........!.........0...............0.....u................................l................................'..k....(..X....@...+.......... R..P(...p..P....,......................................`...4....................................text............................... ..`.data........0......."..............@....rsrc....+...@...,...$..............@..@.reloc..P....p.......P..............@..BM.^7....N.^7%...........KERNEL32.DLL.ADVAPI32.DLL.......................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):325232
                Entropy (8bit):6.249653652844446
                Encrypted:false
                SSDEEP:
                MD5:D7B523EBF27252B6743C051639787F4E
                SHA1:01ABD365CD1E58B4C4EC87C27B425C1B07288686
                SHA-256:8158263E8A4EF27B902F9E33976ED3CD8E46D9B5FBE65121C5D32297169182F0
                SHA-512:0DC107A518FCEC5D368683C78776275B1537B28A010E66E7C5E78BAF679F00AF8A64A63225AF495A8ED8A2134B747F569F1BB73B059A592955064DB93A443690
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............................................Rich....................PE..L...0.C8...........!.........................@....ef.........................@......................................@9.......1..d................... ...P(... ..p...`...........................................l.......`............................text...]-.......................... ..`.data........@...>...4..............@...Shared..P........0...r..............@..P.rsrc...............................@..P.reloc....... ......................@..B4.D80...0[.8=...4.D8G.....+8R...4.D8\...........KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.ADVAPI32.dll........................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):1341520
                Entropy (8bit):6.66010788847487
                Encrypted:false
                SSDEEP:
                MD5:C207037060B84E5C17CF98653BD20ABE
                SHA1:CEACAE377FED65FE061D89BCF49EB82814EAF177
                SHA-256:354C0686968FE623C30802877C63018DCDD180FCB06B567F634C8EC023174DA6
                SHA-512:7789945C12ECEB6DC54CB1C54471E6450CCBC66074E1D92E9D82EBDAAC597E3447B30164B12B051B59F6A5ECB83729E9ACC155FC890CF33F12CC307CECD3E5F5
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...lT:b.....................v.....................Q................................*S..................................R......."6.......Z...........P..P(... .........................................................\.......^....................text...H........................... ..`.itext.............................. ..`.data....O.......P..................@....bss....|S...P.......*...................idata.."6.......8...*..............@....didata.^............b..............@....edata..R............l..............@..@.rdata...............n..............@..@.reloc...... .......p..............@..B.rsrc....Z.......Z..................@..@.....................P..............@..@........................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):2589264
                Entropy (8bit):7.976334352381691
                Encrypted:false
                SSDEEP:
                MD5:8D343DAB03B9193F37F896AECB320C6E
                SHA1:38C2B0A39EC8DDA8682AA31D6129D756BA53CF44
                SHA-256:24745B396401B37240AFB336351D976141822FA7636E572B954B6B875369E260
                SHA-512:2776F378BFDB4E86030E24C00F8DF51604251F916B098BEA466B4B21DE318D3C5D1C917BE09131769CB5FAF53C91F87D1B80D2314ED4D06D6EFFFA1A38C9460A
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......5{.!q..rq..rq..rq..r...rQc.r`..rQc.r`..rQc.rp..rQc.rp..rRichq..r........................PE..L.....A.................~... .......^... ........... ................................'.......... .....................................0............Z'.P(...........!............................................... ...............................text....|... ...~.................. ..`.data...............................@....rsrc...0.........&.................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Template: Intel;1033, Revision Number: {FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}, Number of Words: 0, Number of Pages: 200, Title: Resa Launcher Install, Subject: Resa LauncherInstall Installation, Keywords: Installer, MSI, Database, Author: Wayne RESA, Comments: All rights reserved, Name of Creating Application: InstallAware, Security: 0
                Category:dropped
                Size (bytes):798720
                Entropy (8bit):6.223952255694109
                Encrypted:false
                SSDEEP:
                MD5:C5704BD702D0D1855733D69D8873F14B
                SHA1:FCB229B80BAFBF883C3B587677E9F5FA54DB95A9
                SHA-256:824989A3AB9C7876411ABEEE9772B88667CBF408FADB58549008D3450DFC0690
                SHA-512:2C2FCD2900B0522A188503CCBAC0885517B73523F29E50E688863ECB9862E8032754B8CCDDD6235A385D50F9922EB1153EF3A33B3E25BFDA8B4ECE1565E4372E
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):606266
                Entropy (8bit):6.509399522017653
                Encrypted:false
                SSDEEP:
                MD5:6017C5F8EA6382684DEF62597535B277
                SHA1:1ED79B319B3B0E47BD3B08C194B4CFE1A06F12A8
                SHA-256:F4BB9CF2E03832F23B407D4BDEF1D44D4DFD6A510F2FDC1A6BE263241914B55B
                SHA-512:65A0E4505294C621C031F64051017C9BEE36EF4B5F793C39010A516E84443CD85DBF092A1B4D6526ABEFD499994739326E0B55B2480523DE7C8189B6DD3FF0F6
                Malicious:false
                Antivirus:
                • Antivirus: ReversingLabs, Detection: 0%
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......).n.m...m...m...d.......d...@...J.m.l...J.{.d...m.......d...y...d...%...d...l...s...l...d...l...Richm...........................PE..L....QkT...........!.................e.......0...............................0............@.........................`...........d....0...............................................................................0...............................text............................... ..`.rdata......0......................@..@.data....^......."..................@....rsrc........0......................@..@.reloc...C.......D..................@..B........................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):5541064
                Entropy (8bit):6.435823530860491
                Encrypted:false
                SSDEEP:
                MD5:E0F092BC83227D52E442F13BB3CDE076
                SHA1:00B166E8C8BF425F9522DB9ECD792BCDAA65E066
                SHA-256:F2DD78C0FB10997BC84314E9E2765BB94B2799DB4850D742A2FBD617EDB60870
                SHA-512:3C6CDE01F60F4E3F2F72F043255ECE9FF6B3E33C9A0C65B26166804F0B583BEE48F07C2E95ECAB33554DB90FA6DC9611A45BA33D66D8CE2704B7FBDD1E66BC51
                Malicious:true
                Yara Hits:
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\mia533A.tmp\resa launcher install.exe, Author: Joe Security
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\mia533A.tmp\resa launcher install.exe, Author: Joe Security
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\mia533A.tmp\resa launcher install.exe, Author: Joe Security
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...I=.b..................;..........z;.......;...@...........................Y.....rNU..........@........................... ?..Y...@D..R..........xdT.P(....................................?......................1?.......?......................text.....:.......:................. ..`.itext..t.....;.......:............. ..`.data...4.....;.......;.............@....bss..........=......t=..................idata...Y... ?..Z...t=.............@....didata.......?.......=.............@....tls.....A....?.......=..................rdata........?.......=.............@..@.reloc...L....?.......=.............@..B.rsrc....R...@D..R....=.............@..@..............Y......|W.............@..@........................................................
                Process:C:\Users\user\Desktop\Resa Launcher Install.exe
                File Type:7-zip archive data, version 0.3
                Category:dropped
                Size (bytes):4881982
                Entropy (8bit):6.693300198321919
                Encrypted:false
                SSDEEP:
                MD5:D40BD23363755B7CB745CF714218FD08
                SHA1:8FD6531039368E604FAD6298762B2720AC1C5999
                SHA-256:B8A8C702F3E4B776CA7D57562EDD8FE8F930C3E57EB4918276D80FF7D57A85F4
                SHA-512:BB3F7C28EC8029FD1B92E017EB3AAC3677B0E4B2C85870C5AE84E1C6EDCA5D99BF20C92AB5E6493A82B387192D5149A87E93E2156357DD3286B7E591A702CBA1
                Malicious:false
                Reputation:unknown
                Preview:7z..'....*..uJ.....I.......1."2...TFRMDESIGN.0..-..TPF0.TfrmDesign.Features.Left....Top.b.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):165968
                Entropy (8bit):6.174405424812059
                Encrypted:false
                SSDEEP:
                MD5:7D8C2F20B3342CC2452230EFBFE8F982
                SHA1:7144C8A06FC1154BDC92DF2770487FF1788D1223
                SHA-256:AB45F9BC0BB75DC27769D71F96F9C42A1F83E4DA8C12E424CB83C5EDB243FDC2
                SHA-512:5613500A86F290FC26689ECE4E756C24B412CBE36FB08FF3BF32820E1D0F3CAC8C9B8A3C363547DE264B17E8066A94F8CF7F49D769D0C093D56C51C5086729BA
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........u_A...A...A.......D.......J..............W...A...B...#...H...A...2.......n.......@.......@...RichA...........PE..L.....{:...........!................:..............@............................................................................x.... ..h?...........`..P(...`..8....................................................................................text...%}.......................... ..`.rdata...$.......0..................@..@.data....X.......@..................@....rsrc...h?... ...@..................@..@.reloc..z....`... ...@..............@..BP .:8...P .:E...P .:O.....};Z...P .:g...P .:q...........KERNEL32.dll.NTDLL.DLL.USER32.dll.COMCTL32.dll.GDI32.dll.ADVAPI32.dll...........................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):51280
                Entropy (8bit):5.304894291171389
                Encrypted:false
                SSDEEP:
                MD5:9157CF1FF1703D409C451EA7188237BD
                SHA1:E65ABE9BE0B0542C0E2455A0C2805E842F568257
                SHA-256:1CE6E44FE436C62A380716FE60A9D5E1AE3DC53CC430EB8DFA7C94512FE38390
                SHA-512:FD1BAAFF77BDDE14D36A2307D2F2710AB924E74E91D0346A43A18EC42811A20BBD5334DECC3D8BCE955EA956C1D43E9AEE9EEA4116649FCB18836D6EDB5520AB
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........a.....................h.......................................,...............Rich....................PE..L...7<.<...........!.....P...@......-S.......`......................................$c..............................Pe......Ha..P.......................P(......(....................................................`...............................text....C.......P.................. ..`.rdata.......`.......`..............@..@.data........p.......p..............@....rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):223312
                Entropy (8bit):6.047931325365772
                Encrypted:false
                SSDEEP:
                MD5:807551682D9821A01CC2A9127613D31C
                SHA1:ADEF59D0B76A35BB680538E7851852FE76E44953
                SHA-256:8164A9547E441569854D572B73DBD935EEA1A4C5D728D2E4B0420498AE859D2A
                SHA-512:23DADB0B794B7BF8011ED8ED43B9C672FC7EA9F0805D1C979DD34D07696A2E02767D2A9DE57673BFB142CA9BE19F51AF4459C55B30E42D35D4D486A4A07B0997
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........dW{.7W{.7W{.7,g.7R{.78d.7^{.78d.70{.7.g.7N{.7W{.7K{.75d.7P{.7W{.7.{.7QX.7@{.7.}.7V{.7.[.7V{.7RichW{.7................PE..L...{a9?...........!.....P...................`...............................`......................................@y..(....m..x........N...........@..P(...@..@....................................................`..8............................text....@.......P.................. ..`.rdata..h#...`...0...`..............@..@.data....X.......@..................@....rsrc....N.......P..................@..@.reloc..B....@... ... ..............@..B................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):112720
                Entropy (8bit):5.87701709865469
                Encrypted:false
                SSDEEP:
                MD5:524EAA2DE379BE1B6BD1035902DA9459
                SHA1:A236C3AB00B2C6C533D43F53F7D36E6A594DE196
                SHA-256:553C92B656AF6117AA1AA46C950155565D57B997AE53FDA47A034CEA92D99B7F
                SHA-512:46A53BFE5F5512DED0AC7DF6A011674478ED2DA7C99032A6D6C8C9EC51132F9C6E03A581F8A61CD661D10DC4CD487CA9B70F11B09C3695F156CF5A1683944E17
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......ry.=6.wn6.wn6.wn..sn4.wnk:|n7.wn..yn5.wnk:}n2.wnk:sn4.wn6.vne.wnT.dn0.wn6.wn;.wni:|n+.wn..qn7.wn.8sn7.wnRich6.wn........PE..L.....{:...........!...............................@.................................................................................@...9..............P(..............................................................x............................text............................... ..`.rdata..V........ ..................@..@.data...H.... ... ... ..............@....rsrc....9...@...@...@..............@..@.reloc..............................@..B..C8@.....};L...P .:Y...P .:f...P .:q....3m9{...f..7............CTL3D32.dll.COMCTL32.dll.KERNEL32.dll.USER32.dll.GDI32.dll.MSVCRT.dll.MSVCIRT.dll...............................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):39504
                Entropy (8bit):6.7002671443886275
                Encrypted:false
                SSDEEP:
                MD5:D5F026FC4A2E3D20A81D549AEC240B34
                SHA1:4D07CE9BA478396C92F39FB34A1B5C6047D398AD
                SHA-256:0410E87D4C901B851F3177B2A1AC0D923841940F52CD274234B20237AA56097E
                SHA-512:10032E01A0186B8BEB791536395EC33EF9489E656C7C834EED908E0BA097FEC1F4A6EF035258AD386AE05DCB0C4A31983C9E4926E97B502AF59BC36D6DF79902
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........b.............-.......................Rich....................PE..L...M(M8...........!.....V..........0d.......p.....@................................K]...............................v.......q..d....................r..P(......@....................................................p...............................text...HU.......V.................. ..`.rdata..]....p.......Z..............@..@.data...8............d..............@....rsrc................f..............@..@.reloc...............n..............@..B........................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):51280
                Entropy (8bit):5.413035473149346
                Encrypted:false
                SSDEEP:
                MD5:FF2D67DDC63359174917CB452699D3F5
                SHA1:325F88848E2058B72DA9471DA6B1F74364525B7C
                SHA-256:8C770B9CAFC44AF7FD9BDD45F619AC704986FCD032F60449DBB1B4F355F8B207
                SHA-512:65EE98F8D071B416CB41E971EBA63F7CDB825BAFD8A1B07B8ECD798FC8B4F21E2F7D1B48700BFDECB5BDB2881F7CA11E8F060A417D931CA643E70A26EAC3F4AC
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........X.........V......*..................................*......Rich...........................PE..L.....<...........!.....P...@.......S.......`.......................................*...............................f.......b..P.......................P(...........................................................`...............................text...cD.......P.................. ..`.rdata.......`.......`..............@..@.data........p.......p..............@....rsrc...............................@..@.reloc..F...........................@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):116816
                Entropy (8bit):5.920535499375088
                Encrypted:false
                SSDEEP:
                MD5:06FFACFC42E0ECDBAD6A138D91F7D4BD
                SHA1:0871AF51B44F62AD0A1BAC56FD21E2ED267F2196
                SHA-256:74EDE07C45900B1C2D05C9819481868492A9EB6690DA3A6ECEE14021259C36ED
                SHA-512:F007046C457AF8D7712CCEA0D5F1A69CFC42F08C136B6FEBAC196A115F03BEB02DEE71207940F58456E13086636A13EA65D0C22AEB3E19D8D4568F8536CEC4E8
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............................l....................l.......T.......l.......Rich....................PE..L...J..:...........!.....P...@.......Z.......`......................................................................pm......pg..d.......................P(......@....................................................`..4............................text...zM.......P.................. ..`.rdata.......`.......`..............@..@.data........p.......p..............@....rsrc...............................@..@.reloc..^...........................@..B........................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):235600
                Entropy (8bit):6.216212281733655
                Encrypted:false
                SSDEEP:
                MD5:BABBB3C252010751339A38D4105C09D6
                SHA1:1B414F2062C474074AD770946D8983FEF3E1DB49
                SHA-256:FABF000475FA5B4B4ACBDEB8F7BC71971120B7D71DBBFE2D7BFF86A2C0206D27
                SHA-512:775D6E4EC2D3B9BD9F0130B7D6BD38CF337CFA2B84DE0328201F4D5E1FDE0BC6C1423C56CBB8450EDECDEE1A7E85D1C0B18E079306526C54008A26215C550939
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........P...1.R.1.R.1.R.-.R.1.R...R.1.RZ-.R.1.R...R.1.R...R.1.R.1.R.1.R...R.1.R...R.1.R.7.R.1.R&..R.1.RRich.1.R........PE..L.....3?...........!.........................................................p.......n...............................................0...............p..P(...P..h....................................................................................text............................... ..`.rdata...........0..................@..@.data...4.... ....... ..............@....rsrc.... ...0... ...0..............@..@.reloc..P....P... ...P..............@..B........................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):174216
                Entropy (8bit):6.265966924711891
                Encrypted:false
                SSDEEP:
                MD5:A3DCDADF55A639385C5BD48C558188D2
                SHA1:C6EB2F5F710D880CABDF8E6F542360F8743C4229
                SHA-256:C6E8DB6AA5FCD3A70316E94854981D211DD44695557A30212C1D34550981E532
                SHA-512:E23038C67F0A5F188E0BF2AB3E155A1A194F4F1CAB60BA2C9E6F75FC67D6248CF71DE1246FEFF752E2BDFDC885C140FDEC41C7EFABF313B7C32C3458C55DEAE4
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........iL..:L..:L..:..:N..:#.:M..:#.:H..:#.:N..:..:@..:..:E..:L..:?..:J.:G..:...:M..:..:M..:RichL..:................PE..L...A..<...........!................)...............................................D................................9..i..../.......P..p...........8...P(...`..(....................................................................................text............................... ..`.rdata..)?.......@..................@..@.data...p....@.......@..............@....rsrc...p....P.......P..............@..@.reloc.......`... ...`..............@..B................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):34896
                Entropy (8bit):3.9236739271043386
                Encrypted:false
                SSDEEP:
                MD5:5E11B0AF1B165EFBCA5628CDAEB786CB
                SHA1:AEADA6B4CF95F688FBB0C6D944EABF6946BC0285
                SHA-256:6394B60D61B5511DA0AE8FE3E1DAD76C46521C9B65851BFF9C46497C3DF3C1BC
                SHA-512:00F1F61BB5A4146984E98BAE9EBCBB1CEBEAD6FF47B17D6A97911B057C1F2B694E97E947CA15496478A145E6F27242B56D497BFE36D931B44EA2F41DAB038CC0
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........OD..*...*...*..2$...*...+...*.~. ...*.~.!...*.F(,...*.~.....*.Rich..*.................PE..L...L(M8...........!.........@......!........ .....@.........................`......6(...............................!......` ..(....@...............`..P(...P....................................................... .. ............................text............................... ..`.rdata....... ....... ..............@..@.data........0.......0..............@....rsrc........@.......@..............@..@.reloc.......P.......P..............@..B................................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):309328
                Entropy (8bit):5.96267797924302
                Encrypted:false
                SSDEEP:
                MD5:58E825AE03BCFD966EF91E685A681B09
                SHA1:E9B7182086C79FA41E84B094E11755D75E49794E
                SHA-256:169E5CF558D0DEE9C00125BF633EA84B195051238A304FA56F9B20F68C4F2B22
                SHA-512:4150D17C7D258EA5EC4A3EFBBAFCE927BFAB8D79F3D2A9885DBDC38085780B70D8718CB092220487223E6CE42BB6D4AD1DA24C8D24A913FC54A37AC1494AFF9B
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........0...^E..^E..^E..RE..^E=.\E..^E.ME..^E..^E..^E.._E..^E.ME..^E.UE..^E.TE..^E9.PE..^E.UE..^E.UE..^E}.XE..^EE.ZE..^ERich..^E........PE..L....,_:...........!......... .....................@.................................k...............................6......X...........ha..............P(...@...1......................................................\............................text............................... ..`.rdata..y...........................@..@.data....y...P...P...P..............@....rsrc...ha.......p..................@..@.reloc...s...@......................@..BP .:`...P .:m...P .:w...P .:....R .:....P .:......};....k.M8....Q .:....Q .:.....h.9............KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.WINSPOOL.DRV.ADVAPI32.dll.COMCTL32.dll.oledlg.dll.ole32.dll.OLEAUT32.dll.ODBC32.dll.................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):211536
                Entropy (8bit):6.671110235528254
                Encrypted:false
                SSDEEP:
                MD5:6202DCE65E6796A77219A5700CFB343E
                SHA1:C3D81DA66C5566474D63AD6BDDCDD4A77C3A545F
                SHA-256:FD81F4E8448B08AAEFA6FAA49CA30F7B013238F1B348B5BEB0C807D7F365714F
                SHA-512:72C78737C804D27D099E9779A548DEF50CD4B3530A4E38BDF61760927C86F3C61FCA54471D8A043FCF9E15D72074A96DD122ACE2E5B2810D79D954BEAD7EB6E3
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........ltj...9...9...9...9...9...9...9...9...9Rich...9................PE..L...M(M8...........!.....l..........@u.............@.........................@.................................................P.......................P(.......7...................................................................................text...Nk.......l.................. ..`.rdata..^............p..............@..@.data...DC.......:..................@....rsrc.... ..........................@..@.reloc...8.......:..................@..B........................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):71760
                Entropy (8bit):5.7183937103792974
                Encrypted:false
                SSDEEP:
                MD5:2F51BDCAF7259F352062D676699A829D
                SHA1:0DCD9B886737D4C57B4C0E0ADA2772EE44216669
                SHA-256:26D579E4832ED2387B7096235BC70766A8439B7C48930D2F40E96972FB7C49D6
                SHA-512:485CE8E8C8820D619E9CA1C0C0D5578B2E970BFAC5914A511D4D91793D58CC14BA1068A3644F140155995D57CC88049ECC4A38E3DC5C474C1B91A27936748C52
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.................................................................,.......@......x....Rich...................PE..L.....{:...........!.........`....................\@....................................................................Z...(...........................P(......................................................|....................................text............................... ..`.rdata........... ..................@..@.data...............................@....rsrc...............................@..@.reloc..H...........................@..B.C88....3m9B...P .:M...P .:Z...Q .:e...Q .:o...........MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.ole32.dll.OLEAUT32.dll.....................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):51280
                Entropy (8bit):5.133956741736654
                Encrypted:false
                SSDEEP:
                MD5:612B0737A34463AB93CE0D4472599586
                SHA1:8E5C063ED4697A27B3ED8D758159B8D8FF569144
                SHA-256:41E8C0AB04EE060FBF93285D59C14191891CA67D73E847753DC7FCFA73908000
                SHA-512:53B625B912B9CB8B8D1144E3A4426213A9A2606DF5D783D25A0942B2CCB3D55F71FE2A4551ABA5353F5686BE828E356B44872CC7D22EF793D077E0F7347066A3
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........cu......................................................!......H.......p"......Rich............................PE..L......>...........!.....P...@.......O.......`.......................................G...............................g.......b..d.......................P(......`....................................................`...............................text....@.......P.................. ..`.rdata.......`.......`..............@..@.data........p.......p..............@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):47184
                Entropy (8bit):5.146101537573428
                Encrypted:false
                SSDEEP:
                MD5:3CC6E780AA4C6063E54B9532D929BF8B
                SHA1:698A1EF226239AE8D367833AC43E6C72F0EC6008
                SHA-256:3A354A725074BC430E577E74C066D38CEF28FEAABC5BDA06492AA2A3823D18FE
                SHA-512:87D077578C2EDF20CD3D2366822996D4FCB67A8CA8FFC1C1DEC41BBB2AF877412235D7668F4441E70F78CA0C7BB3606A372ABA5B4FD9437262AD350F5D9781FC
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..................V......*................................*......Rich...........................PE..L.....<...........!.....@...@......GJ.......P.......................................................................T..%...8Q..P....p..P...............P(...........................................................P...............................text....:.......@.................. ..`.rdata.......P.......P..............@..@.data........`.......`..............@....rsrc...P....p.......p..............@..@.reloc..2...........................@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):55376
                Entropy (8bit):4.941337061721676
                Encrypted:false
                SSDEEP:
                MD5:3263525C5508DD9B460151AC31B939C0
                SHA1:98F1ECD588F8C25E7F446E4DBE1543A3A3F20A36
                SHA-256:AC0B4C1ADF31E5256943AA068FF598428170395554C4E2092FA60AE2B97621A9
                SHA-512:0D93799C9312D17AEEAF2042FDD519FE81D8BEE6BEE148A9651824E6594D8039ACD7967EE4BFBBEACD6500FE6B63D0FA478EA2FD6CFB5571EC93883B239DADCE
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Y........................W.....B.............Rich..................PE..L..../;...........!.....P...P.......O.......`......................................................................ph.......a..........................P(...........................................................`..8............................text....@.......P.................. ..`.rdata..-....`.......`..............@..@.data........p.......p..............@....rsrc............ ..................@..@.reloc..<...........................@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):108624
                Entropy (8bit):6.024336014495956
                Encrypted:false
                SSDEEP:
                MD5:26B959B9124B28984E0B8DEE9E79B222
                SHA1:6A9C8FA7BA5ADB3AFC2CB53BE5F3C48FB8C1D15F
                SHA-256:9F4353BBED3E72713AE7E90BD5BB21C67C97362485F4266FBCAE98A96316B02C
                SHA-512:6F1609BBC18E2C3AB3FA7D2474A6C4B0E114844670B8D34AC6806B625FB4E95A4F0A7170012ADE8D5BDAAB159F0677CD5B77305625DA0EDC03ED1583A4FECBF1
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......U.K..m%..m%..m%.jq)..m%.LO...m%..q+..m%.LO/..m%.LO!..m%..m%..m%..m$.Wm%.sr6..m%.NO...m%..k#..m%..M!..m%.Rich.m%.........PE..L...SO.:...........!..... ...P......E!.......0......................................;...............................09.......3..x....P..X...............P(...p..`....................................................0..|............................text...:........ .................. ..`.rdata.......0.......0..............@..@.data........@.......@..............@....rsrc...X....P... ...P..............@..@.reloc..b....p.......p..............@..B................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):67664
                Entropy (8bit):5.597966766976955
                Encrypted:false
                SSDEEP:
                MD5:53DC52A678B395FCDE57FFA70B674564
                SHA1:203C6F145DFA023AF9A769D2A8BD6AC0FE9610DC
                SHA-256:6227A31D4BDE248D44F11EAE424C70EBA1F0D987341C6FFD04FB3B85EBBF9384
                SHA-512:73588C4A0CFF8AEE6874205EA55F27BDFB441E1CA947BB5DB8DBDF0A4FD0EF7135D65471978521A6333F08F45241E63F84663683F44AC715BBC414D5A37F8F10
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........^~..?...?...?...#...?..H#...?..4....?...?...?... ...?..4....?...9...?..4....?..Rich.?..........PE..L...J(M8...........!.........P....................k@................................................................p...........P.......................P(...........................................................................................text...3........................... ..`.rdata..............................@..@.data...............................@....rsrc............ ..................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):38992
                Entropy (8bit):4.504721040611216
                Encrypted:false
                SSDEEP:
                MD5:A1B4B6605EB4413A56A1403DA296E6C5
                SHA1:F0FFB9F33149EC502AF2194E884D247C980CFE6C
                SHA-256:7B582773BAA49939CBD77A7E5CCEF5FA24F43134A72A44C1FF4E10AA3E9E406A
                SHA-512:B454EC7A8EA3850C91BEF295B7984546DC515C435807146D131A726A0B781D112B3BC53F0B0891B732D69B9BB758530440BF2C350FF6CE1FA60CCF7993FEF4B6
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........................@......<......................................<.......Rich...........PE..L...D.5<...........!..... ...@.......'.......0...............................p......N................................4.......0..x....P...............p..P(...`.......................................................0...............................text...`........ .................. ..`.rdata..X....0.......0..............@..@.data...T....@.......@..............@....rsrc........P.......P..............@..@.reloc.......`.......`..............@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):198736
                Entropy (8bit):5.3372990427038225
                Encrypted:false
                SSDEEP:
                MD5:2FF2D6DC5303C955E1EC32E43DB4698A
                SHA1:BDBFCF97F63C7FB56DE628ACF23FED19F6D2E329
                SHA-256:E7A5F1E03CEDB1430B8F6890BBA09194121C18B24A22520C73D06D5D069A81FD
                SHA-512:B7D661FEECC1CBD1CBF51DAC17683CB4AB0D4F93D02B78335FBDA9BC859A5F2FD51EA492B363EB5D47EB2E6BB33056FDB4B787164C25A9AF7E922A32CDCD4609
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......xL.9<-.j<-.j<-.jG1.j9-.j.1.j=-.ja..j=-.ja..j8-.ja..j>-.j.2.j>-.j<-.j:-.j<-.jD-.j^2.j1-.jc..j&-.j.+.j=-.j...j=-.jRich<-.j........PE..L.....{:...........!...............................@.........................................................................p..........)U..............P(......x....................................................t...............................text...z........................... ..`.rdata........... ..................@..@.data...\F... ... ... ..............@....idata..t....p... ...@..............@..@.rsrc...)U.......`...`..............@..@.reloc........... ..................@..B. .:P.....};X...P .:e...P .:r...P .:}...U .:....P .:....f..7.....3m9............MPR.dll.COMCTL32.dll.KERNEL32.dll.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.MSVCIRT.dll.MSVCRT.dll.........................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):88144
                Entropy (8bit):5.414786226868463
                Encrypted:false
                SSDEEP:
                MD5:028DA3028706A3882158584422F8EE44
                SHA1:8BC1DF00A24AE82B66C13BE579A6247636D7752C
                SHA-256:7AA28D367241ACDFDA2F0C196E65690F0E77654ADD5E94B43579DA5AE0CA2DDB
                SHA-512:DAB3DED6558589C9261FFCADA49F128CCE5E0935F88AD9859DC1372E9B76D4CC7BC6B0EE8AD20470614B2B9BB801A3AA17D60B1BC868D021DD128B0705F8944F
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........n..E..E..E..>..G.....D.../.D.../.A..E.....E.....'..@...-.D...-.C.....D.../.F..RichE..................PE..L...0..<...........!................q........................................0.........................................t...x...x........0...........0..P(... .......................................................................................text... ........................... ..`.rdata..T........ ..................@..@.data...............................@....rsrc....0.......@..................@..@.reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):34896
                Entropy (8bit):3.833143032805
                Encrypted:false
                SSDEEP:
                MD5:54A9DD70E2AAA9FF1E23E338CEAFDC46
                SHA1:B526CDFF85BAF3ABC9F285BB2F776266D52C394E
                SHA-256:FC68417198B4B0902A212449DCF125811BFAB143E8E2F80F1334EDA1F7050C4F
                SHA-512:13FF0103D9B12C3AC3EA85B82A3C1556BF2567FDE74CA179B35C183B52AF430D780F0BEA6DDC309757D13157FDA416D524BBD2276F34FCFE717531F6873603CF
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......y./.=.A.=.A.=.A...O.<.A.=.@.1.A._.R.>.A...K.:.A...G.<.A...E.>.A.Rich=.A.........................PE..L...L(M8...........!.........@............... .....@.........................`.......H..............................P!..Y...` ..<....@...............`..P(...P....................................................... ..0............................text...T........................... ..`.rdata....... ....... ..............@..@.data........0.......0..............@....rsrc........@.......@..............@..@.reloc.......P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):67664
                Entropy (8bit):5.272275597822636
                Encrypted:false
                SSDEEP:
                MD5:4E1DEF1AB0400564554F47ADF13DE9E0
                SHA1:12C5B56486070288A86B17DF5B5CE8C94EAD278F
                SHA-256:CF97D4094B4F276DA3273BC7D6F9C8F3E8337D31241707295FD05396F4E809C8
                SHA-512:762A64FB8C57DE644DE0BB4209D5659B12FC9A7D23830AB3C0F927A7AAD04D247BDE323CAF75852ED7B6F28A2413917C54D5374C72F3EC3080B250EF71FAFD92
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........^yz.^yz.^yz.1fq._yz..et.Kyz.1fp.dyz.^y{..yz.<fi.]yz.XZq.Ayz..|._yz.Y~._yz.Rich^yz.........................PE..L.....V<...........!.....`...........,.......p.......................................................................}......ty..(.......p...............P(...........................................................p...............................text...6Z.......`.................. ..`.rdata..p....p... ...p..............@..@.data....5.......0..................@....rsrc...p...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):88144
                Entropy (8bit):5.8973823306292905
                Encrypted:false
                SSDEEP:
                MD5:EF3BC42560F21168AFD7D1B88F7D9859
                SHA1:DDD913C80DD41E91DECE5CC83F4C9676BDF028FB
                SHA-256:6CE9588465210CE8D164CF35421816F16A16159149C6F7D4BF50AC7421CBC52E
                SHA-512:E724AFE946EF8F3ED01FA32722490058F74C464379C08069401DBF2B852DA811AE6C433C35F6CDD292A7A0FC5E63099E01916249DE0281C2368BA6087C28AF4C
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........lG...)...)...)..%...).V.'...)./"...)./#...)./-...)...)...)..:...)...(..)..:...)./"...).../...).*--...).Rich..).................PE..L.....{:...........!..............................@.........................@......T....................................... ............<...........0..P(...0..H....................................................................................text...E........................... ..`.rdata........... ..................@..@.data...............................@....rsrc....<.......@..................@..@.reloc.."....0....... ..............@..B. .:P...7.D8X...P .:d...P .:q...U .:|...P .:....R .:....Q .:.....3m9............MPR.dll.VERSION.dll.KERNEL32.dll.USER32.dll.comdlg32.dll.ADVAPI32.dll.SHELL32.dll.ole32.dll.MSVCRT.dll..........................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):120912
                Entropy (8bit):5.141608645914375
                Encrypted:false
                SSDEEP:
                MD5:9982225CCA3DA932AC51FE1B21BC7E5A
                SHA1:5A21FAE294C78758FB6B57F29ED133869FD46FEC
                SHA-256:B035D7A6AC4A98CC54B6B9F120C391FCECBDBB0A568FA7435D9C2D1E65143F00
                SHA-512:DA24D238349560D43F4640EE5290BC7E5B41578294CE0BD3CF7585A53744A02F4567738E0C425944D76FB57065FDDF8F6377B9E3F454F74B576CA438F6DB4236
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......."..Jf...f...f......g.......b.......d...f.......?...i.......g.......~.......e...Richf...........................PE..L....Y.:...........!...............................@.........................................................................P.......`...N..............P(...........................................................T..T............................text............................... ..`.rdata........... ..................@..@.data...(....0.......0..............@....idata.......P.......@..............@..@.rsrc....N...`...P...P..............@..@.reloc..0...........................@..B. .:P.....};X...P .:e...P .:r...P .:}...U .:....P .:....f..7.....3m9............MPR.dll.COMCTL32.dll.KERNEL32.dll.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.MSVCIRT.dll.MSVCRT.dll.........................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):47184
                Entropy (8bit):4.970075233580217
                Encrypted:false
                SSDEEP:
                MD5:10B604DCB96E6821E1AB711A7526E2F2
                SHA1:FE3DDA05B70E9394E25928CCF89EFFC2B9C03564
                SHA-256:2CB5D96E657A35ED877F64FA4D1E7C8025AED0689C4ED6D2B7A7715B03DCE527
                SHA-512:6E236FD7A9D172794861A56B0F8167DB6861B71582AEB1CA2FCAF405E268EF3ADED885E80FA04CCF8C8B1E570DBBB48CD5FBA3683A18A71C810041EE11D2DA52
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........7M..V#..V#..V#..J-..V#.hv)..V#..V"..V#..I0..V#..t(..V#.PP%..V#.hv'..V#.Rich.V#.........PE..L...F..<...........!.....@...@......]D.......P......................................~Y..............................0U..%...HQ..d....p..p...............P(...........................................................P...............................text....5.......@.................. ..`.rdata..U....P.......P..............@..@.data........`.......`..............@....rsrc...p....p.......p..............@..@.reloc..R...........................@..B................................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):292944
                Entropy (8bit):6.148311052344073
                Encrypted:false
                SSDEEP:
                MD5:E5EE6111206E03328B514A993D203F54
                SHA1:5CB7DDBBE6D95D661A3CBCF1031E5496CBC93025
                SHA-256:53F48084667F866904AC078E80DF8C9FB3D2CB73E38F63EA6883C1273761386D
                SHA-512:F94B6C7AB90C4C72F848B49C38EC5F5DB57422EF52F2D2122D7A9AF7D1D5B1B81D6E6ACDC541B791CA448CB6F45E1CED246C2DB1A4F5FA450DB6BFE42A74A386
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........q.........................2......2..............1....................2.....N......v0.....Rich....................PE..L.....{:...........!.................i............{@.................................)...............................&...................m...........P..P(... .......................................................................................text............................... ..`.rdata..K...........................@..@.data...`|...0...P...0..............@....rsrc....m.......p..................@..@.reloc..8S... ...`..................@..B. .:X...P .:`...P .:m...P .:w...P .:....U .:....R .:....P .:......};....Q .:............MPR.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.WINSPOOL.DRV.ADVAPI32.dll.COMCTL32.dll.ole32.dll...............................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):38992
                Entropy (8bit):4.434749682619407
                Encrypted:false
                SSDEEP:
                MD5:B44FE084D2D3E95789D5826F28A8C2C7
                SHA1:BEDB0CF79F4838000719C59C1F6A3B828FF579AD
                SHA-256:12815317C11192CD16A157EA0F82480B1032F2C95AC75F2503010E33595E7A66
                SHA-512:7A50075C65787E06F042E8018635F2CEAC4F0A2B13B40B12BB8C728EA0060233A7516A5B684AB6CC2BA2AE133EDA4B6F7D162FB2245ECE42515D94B8C252EC18
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......k.a./k../k../k...w...k..rI..+k..rI..-k../k...k..Mt..*k..pI..,k...m...k...K...k..Rich/k..........PE..L...B.|:...........!..... ...@.......$.......0.....@.........................p......c................................3.......0..P....P...............p..P(...`..................................................D....0...............................text............ .................. ..`.rdata.......0.......0..............@..@.data........@.......@..............@....rsrc........P.......P..............@..@.reloc.......`.......`..............@..BP .: ...P .:-....3m98...........KERNEL32.dll.USER32.dll.MSVCRT.dll......................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):235600
                Entropy (8bit):5.861660187888396
                Encrypted:false
                SSDEEP:
                MD5:88DF1942855169CBFE5E6C3239258AFC
                SHA1:81FAA8A28ED4E0B60664B76E57EA6754F19492D3
                SHA-256:604E49AE01FDEEF15598069BE810910C56E627AB54520A69451853BBA91CFDEB
                SHA-512:86071A95FE47300BCD5652E18A4C0BF0EDA5EDF685502F829ADFC0A9B26C78D75458E797DC277B3069235BF275C59BDDAAF404C98D70CA95ACEC4B4C5A13B6EA
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......@ .w.A.$.A.$.A.$.^.$.A.$Yc.$.A.$.].$.A.$Yc.$xA.$f^.$.A.$.A.$wA.$[c.$.A.$[c.$.A.$.G.$.A.$.a.$.A.$Rich.A.$........................PE..L.....{:...........!..... ...`.......{.......0.......................................H...............................O......xF..d....@...............p..P(...`..................................................l....0...............................text............ .................. ..`.rdata..:$...0...0...0..............@..@.data...Q....`.......`..............@....rsrc........@... ... ..............@..@.reloc... ...`...0...@..............@..BP .:0...P .:=...P .:G...P .:R...U .:\...........KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):197712
                Entropy (8bit):6.335331716314497
                Encrypted:false
                SSDEEP:
                MD5:86F1A40BDD7ACCBFC336F0D9893C600C
                SHA1:2E89EFE740F9CC2FB6A46D057B41438ED9838D57
                SHA-256:A4261333BFE182EC15666EC8244B599E93C556E33C2EC50162F653CC42AA3A0E
                SHA-512:FC2D8FC209FC6649D5B4FF18E5B975A223D5CE7EF230F09873E2F947585D5B6407763FBC4FC85785CEF493F761C51A1A4A7A94A286C086111A7A23B2B5E1F028
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........'~S.F...F...F...F...G...@...F...Z...F..Rich.F..........................PE..L.....B?...........!.....8..........@........P...............................0.......................................i......8a..d.......................P(...........................................................P...............................text...h6.......8.................. ..`.rdata.......P.......<..............@..@.data...@d...p...N...Z..............@....rsrc...............................@..@.reloc..H!......."..................@..B................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):686224
                Entropy (8bit):6.367986897794265
                Encrypted:false
                SSDEEP:
                MD5:74B9A1D7053CA0B271F0AB72C0C64383
                SHA1:44973DCD77ED328DA8CB74B7F455424F5FD5CF3B
                SHA-256:6960778FA5C7A4C14A574E44C6E5367637F063663772C831B3B79DA2D3F4D367
                SHA-512:4011EB3615DF3F7DD197030E4556808617AB7E4C9EFC90215772BB3F412ACC1E6B62AD6FE1291D383AB9031754D45F16298692B8FECF3BB6329DF4B8661FF1F4
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$........=Y.V\7.V\7.V\7.C<.U\7.-@;.T\7..C$.U\7.V\7.Q\7.9C<.U\7..@9.U\7.9C=.R\7.9C3.T\7./}<.U\7./}3.T\7.|<.Z\7.|=..\7.V\6.^7.4C$.E\7.P.=.T\7.P.<.y\7.Z1.W\7.|3.W\7.RichV\7.........................PE..L...e6.?...........!.........`...............................................`.......................................D......$6......................@P..P(.......T...........................................................5..@....................text...N........................... ..`.rdata...U.......`..................@..@.data........P.......P..............@..._CODE...p...........................@....rsrc...............................@..@.reloc..p...........................@..B................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):5052560
                Entropy (8bit):6.352466386076086
                Encrypted:false
                SSDEEP:
                MD5:736B3AA2B9A7B77050FA501873D8DE13
                SHA1:B0C5323BD1C04547C324FF603C571928A28FB8F5
                SHA-256:F27381F3FB5E32E502A52A896D2782AE9DB89377D9CB07DB4A16E952E633CC6B
                SHA-512:1B12EF6D13B47EFD6A4154A26BF1A21A696CF2DAEE0E0DBD3D806095559F6B2C13EC17E29BD43F77583A70CBFBA69B31644EBAFE0E44294B8FB85A64C4F8A5E3
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$.........."..q..q..q..q..q...q..q..q..q..q..q..q..q..q..qn..q..q..q..q..q..q...q..q...q..q..q..q...q..q...q..q...q..q...qb.q*.q..q...q..qRich..q........PE..L...[..?...........!......4.........c.2.......5...............................M.......M.............................0J<..j..,.<.......?............@.L.P(....I. ^..P.5...............................................5.P.....<.@....................text...~.4.......4................. ..`.rdata........5.......5.............@..@.data.........<.......<.............@..._CODE....*....>..0...@>.............@....rsrc........?......p>.............@..@.reloc........I...... I.............@..B................................................................................................................................................................................................................
                Process:C:\ProgramData\{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}\OFFLINE\mFileBagIDE.dll\485E7F52\Crystal 8.5 for W11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):1390160
                Entropy (8bit):6.6815219018884715
                Encrypted:false
                SSDEEP:
                MD5:203CEF9A5BBCDEC9D234B6951337563D
                SHA1:4258337A2A3AE206B6118A9BF17E8B688C6925C5
                SHA-256:479BC67938348F569394DFBE4E410EBBADECE156D3EE895847EEDB518BAC98D9
                SHA-512:F44081F778464938123BB43A3E569600F1ECA364CC86223F5B233F7586720464558B3864F8920C52BEEE55CC4C021053759FCF9F2B8ED117BD60E707C35910C9
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...uT:b.................~.........................Q....................................................................O....P..@=...`...Z..............P(..........................................................d[..\............................text....i.......j.................. ..`.itext...............n.............. ..`.data....O.......P..................@....bss....(T...............................idata..@=...P...>..................@....didata.............................@....edata..O...........................@..@.rdata..............................@..@.reloc..............................@..B.rsrc....Z...`...Z..................@..@....................................@..@........................................................
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):240
                Entropy (8bit):5.170379201408242
                Encrypted:false
                SSDEEP:
                MD5:D36D6E3A6AA5C5CEE2DADEED6BA7AE9A
                SHA1:AE7E343DEE2A5F939A3F588244A2E2EF6568FCC6
                SHA-256:FFE1B7019C080224003F1E36F72DEC496677486DF4B8444B251E9F348197BA0D
                SHA-512:FDB596DC5B3B347EF8A31DF9A1F6F97F68B76D9A6B7096EB592B33F834F8566B742F15C78059A03142BB14CA17887B56D0E82E65584C52B46045A0EBA3A7C26C
                Malicious:false
                Reputation:unknown
                Preview:MYAH-PREDEF-COMPONENT..$..TRUE..$..$..$..$..MYAH-PREDEF-COMPONENT..23318464..$..C:\ResaApps ..TRUE..Crystal 8.5 for W11..C:\PROGRA~3\mia7875.tmp\data\..MYAH64WOW..Win32..OVERRIDECACHE....NATIVE_ENGINE..FALSE..ANAPPLYINSTALLWASCALLED..TRUE..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):5567944
                Entropy (8bit):6.4442376778482595
                Encrypted:false
                SSDEEP:
                MD5:A67A337BC7C5734284BC8362A9E98D96
                SHA1:39258146BE00940253B6C4471C23164BCD6E067D
                SHA-256:9B16F0B62FF281A8A8C8BEB1FD19E074CB6C7D692A1C70C42E211FF5DA8F172E
                SHA-512:B8234CEA57D9EE33E71143A9151382FF2D2A012CE3FA221E8A1E317F30CC8417A4624117E2EABB26F031885FE2D8E969E07F7E92B0804FDFACAE5579D3D97D81
                Malicious:false
                Yara Hits:
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\{34298CBE-CEDC-4FE1-85C1-841B00345C2F}\crystal 8.5 for w11.exe, Author: Joe Security
                • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\{34298CBE-CEDC-4FE1-85C1-841B00345C2F}\crystal 8.5 for w11.exe, Author: Joe Security
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...I=.b..................;..........z;.......;...@...........................Y......^U..........@........................... ?..Y...@D..R..........x.T.P(....................................?......................1?.......?......................text.....:.......:................. ..`.itext..t.....;.......:............. ..`.data...4.....;.......;.............@....bss..........=......t=..................idata...Y... ?..Z...t=.............@....didata.......?.......=.............@....tls.....A....?.......=..................rdata........?.......=.............@..@.reloc...L....?.......=.............@..B.rsrc....R...@D..R....=.............@..@..............Y......|W.............@..@........................................................
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                Category:dropped
                Size (bytes):9844
                Entropy (8bit):5.058107588546555
                Encrypted:false
                SSDEEP:
                MD5:3A9230415D2C23FB8075F68D988E335F
                SHA1:6D7674307CD91971895B59D28366B63BFD1CFB1F
                SHA-256:EAB9E40919EA3239B8463116919AF8643C827D189E97ADFE7B13FEAA1B9B1D89
                SHA-512:AB4B7E2CEEFA438824CE5D45A5F0CC2297014F24564C8E778723FE495100ABF69992A60A57929738A7728FB89FD0B399710DBBF7AA3BD51AB31FC5AD8D0E3526
                Malicious:false
                Reputation:unknown
                Preview:.A8B01F5B2..FALSE..A883718..FALSE..ACABD959B..FALSE..A26E8E8A..FALSE..A94B3D4EC..FALSE..AE32DAA77..FALSE..A726C68BE..FALSE..A2AFBF32D..FALSE..A5161E481..FALSE..AE6C13C9B..FALSE..AA601C89B..FALSE..A13DA35D8..FALSE..AD9EFCC70..FALSE..AD446D6EB..FALSE..A6DC047F3..FALSE..A8FDFB1D7..FALSE..A455F3481..FALSE..A3BB8A745..FALSE..AB7A0E9B3..FALSE..AF91D79CA..FALSE..A8E3B9392..FALSE..AFACCD2C0..FALSE..ACE415E54..FALSE..A1041948F..FALSE..AAC2FB922..FALSE..A14806AD8..FALSE..ADA3FBFCA..FALSE..AFCFCFB4F..FALSE..A8489469B..FALSE..AF638DC57..FALSE..AA3E37DC2..FALSE..A4172DCD0..FALSE..AC01F740C..FALSE..A30081FF8..FALSE..AEF13AA58..FALSE..A7AD5685D..FALSE..A3E127F46..FALSE..A412317AF..FALSE..AC4C6F595..FALSE..AD7C8AF63..FALSE..AD94C387D..FALSE..AA3914D62..FALSE..A9FBC96CE..FALSE..A13BF4A53..FALSE..A3E8BEE2A..FALSE..A5F8D9202..FALSE..A9182ED79..FALSE..AE64120EF..FALSE..A41230ACA..FALSE..A7BFE20FE..FALSE..A4D4C9950..FALSE..A5C718172..FALSE..AF9EDC056..FALSE..ABD9F54F0..FALSE..A70A680E..FALSE..A9F86AF91..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):101
                Entropy (8bit):4.700561885388248
                Encrypted:false
                SSDEEP:
                MD5:860C1933F6E0277340AFB01D13E73C9F
                SHA1:610038408061CB494D82037614411B64FF10893E
                SHA-256:CF5C01C1E46BE4BC6E5CB10CF6CF826E68A9D2BF172413DE14AB5E1957389F55
                SHA-512:96C18D61DDFFAB14D3387D2F662E5E545404FE84E785F50B2EF885F0B50339AAC8637C308E7E68CD154C3477BE4F41068BE98DD4C180D2950036066F02F1F493
                Malicious:false
                Reputation:unknown
                Preview:{D19A7273-0D14-44C3-95A2-2FBB862BA70E}..{34298CBE-CEDC-4FE1-85C1-841B00345C2F}..Crystal 8.5 for W11..
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):103
                Entropy (8bit):4.842274828365732
                Encrypted:false
                SSDEEP:
                MD5:DA6DD9A57835F6E2FD1282A4040E1618
                SHA1:57D46A069F88232C9EBBE0BF5D8D5546615EEBDC
                SHA-256:E52271BA0372B84CEB5C2462C8090ED25BF54F3E5EAB92C09A586591BBAE5DE6
                SHA-512:53B6DFA85F61E17A5F4C598C9B7FFAC0C05272E2955EFB3EA6CCB67C41F112F5117F4ED30C3CC90543B0482EEC2D691A6E112771674CE5D7DEDCAFB72329A4CA
                Malicious:false
                Reputation:unknown
                Preview:{7F9E06BB-5B40-4E0F-91B1-6A37A71A3390}..{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}..Resa Launcher Install..
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):0
                Entropy (8bit):0.0
                Encrypted:false
                SSDEEP:
                MD5:6017C5F8EA6382684DEF62597535B277
                SHA1:1ED79B319B3B0E47BD3B08C194B4CFE1A06F12A8
                SHA-256:F4BB9CF2E03832F23B407D4BDEF1D44D4DFD6A510F2FDC1A6BE263241914B55B
                SHA-512:65A0E4505294C621C031F64051017C9BEE36EF4B5F793C39010A516E84443CD85DBF092A1B4D6526ABEFD499994739326E0B55B2480523DE7C8189B6DD3FF0F6
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......).n.m...m...m...d.......d...@...J.m.l...J.{.d...m.......d...y...d...%...d...l...s...l...d...l...Richm...........................PE..L....QkT...........!.................e.......0...............................0............@.........................`...........d....0...............................................................................0...............................text............................... ..`.rdata......0......................@..@.data....^......."..................@....rsrc........0......................@..@.reloc...C.......D..................@..B........................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):252
                Entropy (8bit):4.89264482132292
                Encrypted:false
                SSDEEP:
                MD5:4BB3AA903A52594A12369B7740DD5E8C
                SHA1:DF13EAAA25C8A58A487F6B1FE7FB41E137A81922
                SHA-256:9C8BE6036C8565BE0FA7A6CFABF44402DDF71A15AAE8334B134AD2000A24C737
                SHA-512:F6DC5C209BA9667915189A9693493D4F3E6E405CD819C8B40740CFF1938393C6F7E9B03BF99928C4C882CB01E184DE7BD8D72E4B0D94F61AC42AA52A7CD893D5
                Malicious:false
                Reputation:unknown
                Preview:MYAH-PREDEF-COMPONENT..Version1..$..TRUE..TRUE..$..$..$..$..MYAH-PREDEF-COMPONENT..14114112..VERSION1..0..$..C:\ResaApps..TRUE..C:\ResaApps..C:\PROGRA~3\{FF44E~1\..MYAH64WOW..Win32..OVERRIDECACHE....NATIVE_ENGINE..FALSE..ANAPPLYINSTALLWASCALLED..TRUE..
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):0
                Entropy (8bit):0.0
                Encrypted:false
                SSDEEP:
                MD5:E0F092BC83227D52E442F13BB3CDE076
                SHA1:00B166E8C8BF425F9522DB9ECD792BCDAA65E066
                SHA-256:F2DD78C0FB10997BC84314E9E2765BB94B2799DB4850D742A2FBD617EDB60870
                SHA-512:3C6CDE01F60F4E3F2F72F043255ECE9FF6B3E33C9A0C65B26166804F0B583BEE48F07C2E95ECAB33554DB90FA6DC9611A45BA33D66D8CE2704B7FBDD1E66BC51
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...I=.b..................;..........z;.......;...@...........................Y.....rNU..........@........................... ?..Y...@D..R..........xdT.P(....................................?......................1?.......?......................text.....:.......:................. ..`.itext..t.....;.......:............. ..`.data...4.....;.......;.............@....bss..........=......t=..................idata...Y... ?..Z...t=.............@....didata.......?.......=.............@....tls.....A....?.......=..................rdata........?.......=.............@..@.reloc...L....?.......=.............@..B.rsrc....R...@D..R....=.............@..@..............Y......|W.............@..@........................................................
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                Category:dropped
                Size (bytes):599
                Entropy (8bit):5.1074490420893675
                Encrypted:false
                SSDEEP:
                MD5:1A07914747DF85A82C5D1893AB29B381
                SHA1:398F709E0D6B55DDE4B4148500B3582151937E29
                SHA-256:166CD7AD909C062A2261D6A5F31746C856706B7EA5E9F811B310767E0CBFF45E
                SHA-512:847F231883B8B12D9BF886FE118909B6EAB438B23149631153D5FE89723D268368A7CA90D12501359EC2E5D8A5EDE5743E168C301F41ADA5BF46A2EB1B188D83
                Malicious:false
                Reputation:unknown
                Preview:.A607A9F5C..FALSE..A8E136A7B..FALSE..A851024AE..FALSE..AF82E73DF..FALSE..A5D8AC0F0..FALSE..AF4142F16..FALSE..A607A9F5C..TRUE..P607A9F5C_1..C:\ResaApps..A8E136A7B..TRUE..P8E136A7B_1..C:\Users\user\Desktop\..P8E136A7B_2..C:\ResaApps\ResaLauncher.exe..P8E136A7B_3....P8E136A7B_4..C:\ResaApps..A851024AE..TRUE..P851024AE_1..C:\ResaApps\Business_Services..AF82E73DF..TRUE..PF82E73DF_1..C:\ResaApps\Reports..A5D8AC0F0..TRUE..P5D8AC0F0_1..C:\ResaApps\Business_Services\TaxControls..AF4142F16..TRUE..PF4142F16_1..C:\ResaApps\Business_Services\TaxControls..MSINTEMP..C:\Users\user\AppData\Local\Temp\..
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:7-zip archive data, version 0.3
                Category:dropped
                Size (bytes):0
                Entropy (8bit):0.0
                Encrypted:false
                SSDEEP:
                MD5:D40BD23363755B7CB745CF714218FD08
                SHA1:8FD6531039368E604FAD6298762B2720AC1C5999
                SHA-256:B8A8C702F3E4B776CA7D57562EDD8FE8F930C3E57EB4918276D80FF7D57A85F4
                SHA-512:BB3F7C28EC8029FD1B92E017EB3AAC3677B0E4B2C85870C5AE84E1C6EDCA5D99BF20C92AB5E6493A82B387192D5149A87E93E2156357DD3286B7E591A702CBA1
                Malicious:false
                Reputation:unknown
                Preview:7z..'....*..uJ.....I.......1."2...TFRMDESIGN.0..-..TPF0.TfrmDesign.Features.Left....Top.b.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):190600
                Entropy (8bit):6.307874504201113
                Encrypted:false
                SSDEEP:
                MD5:AFF082F1A9C80CC028154F24A05FEA43
                SHA1:4B25A2C3591446B57058D5EB8C0C037C271D2B47
                SHA-256:33B9156A21E7D28BC6240945CC39235384A81412ADE7AD6B569ABD6B47FBF567
                SHA-512:CD1F3A82BDA5489CB49F20002160AAE5781C4899584495D3C2B439D625321233EFAB5C022FF51AB199D5B664E57FEC33830A41BD7B1C1DC6C5C0679A3B04A71E
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........lx..+..+..+...+...+...+...+p..+..+...+...+...+...+..+...+...+...+4..+..+...+..+Rich..+........................PE..L...M..;...........!.................B....... ...................................................................... ].......Q..x...................8...P(..........0"............................................... ..0............................text............................... ..`.rdata...?... ...@... ..............@..@.data...08...`...0...`..............@....rsrc...............................@..@.reloc..l........ ..................@..B................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):100432
                Entropy (8bit):5.7592641511358185
                Encrypted:false
                SSDEEP:
                MD5:7EC4A00D351A42F7FD67D0909669EDEA
                SHA1:0A8E555854AB2B8F3C97D6606C0C1DA282D88795
                SHA-256:9769B5C5CFD434C4620F66004E47D1E4F55364D6015233F42C259C9FB9D78A51
                SHA-512:B1A45C487DD214D884D57494D04479125027F803F8F9A6BF97C74D74CD81D43AE9B3557BF0788EE431BC2B570513221A2E75A10D593619710CEA92E27BA61AB0
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......a)4.%HZ.%HZ.%HZ.^TV.!HZ..TT.'HZ.xjQ.$HZ.xjP.!HZ.xj^.'HZ..W^..HZ.%H[.eHZ.GWI. HZ.zjP.$HZ.zjQ.!HZ..N\.$HZ..h^.$HZ.Rich%HZ.................PE..L.....{:...........!.........`......Y.............n@.........................`..................................................d....0...............`..P(...P..................................................X.......|............................text............................... ..`.rdata..............................@..@.data............ ..................@....rsrc........0... ...0..............@..@.reloc.......P.......P..............@..BP .:(...P .:5.......@....3m9M...........KERNEL32.dll.USER32.dll.isqlt09a.dll.MSVCRT.dll.........................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):112720
                Entropy (8bit):6.040847816795776
                Encrypted:false
                SSDEEP:
                MD5:F0AC5510F2ADF13B88C5C8883A63931C
                SHA1:55282D48F893E36550E8009191091CF9247101D1
                SHA-256:F3CF50996B8F0EC3E0B1205E84E9B2B315AF53579B05B0F5E18BDB930AD31A45
                SHA-512:E47A25F75B1608FB52E03519052B1D24B4B83563192D134129747D2F7600AF5E95FD0CCC833A4CBC87F85B2CCD721A468AA977CEDF473823BD7BF86BEB2095F7
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..................................".................................................f.......^.......Rich............PE..L...`A.:...........!.....0...`.......5.......@......................................T................................H.......C..d....p..8...............P(...........................................................@..X............................text....'.......0.................. ..`.rdata..q....@.......@..............@..@.data... ....P.......P..............@....rsrc...8....p.......`..............@..@.reloc........... ...p..............@..B................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):165968
                Entropy (8bit):5.972185338899497
                Encrypted:false
                SSDEEP:
                MD5:379DEEB9AA4C321C41BCE3948E9911F5
                SHA1:B4BE31144BF20F16126631EDC45898AECA2D5026
                SHA-256:CA1A87E19761264D57D45C11A1DEF61BEDD493E56DBE1ABCF7090D94B72DAC6A
                SHA-512:707D91EEC55EA0FB48BDF3B052C61F25FD352A88E72CEE4B968F8B0DD6551074397501C477138AE81B077E5546D335ADE3928D3286F99A968EBD454034380277
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K.X.*...*...*...6...*.......*.......*...6...*...*...*...5...*...*...*.......*..A,...*..y....*..Rich.*..........................PE..L...<Q.:...........!.................C..............................................,...........................................d....@...............`..P(...`..H....................................................................................text............................... ..`.rdata........... ..................@..@.data....U.......@..................@....rsrc........@... ... ..............@..@.reloc.......`... ...@..............@..B........................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):108624
                Entropy (8bit):5.649802054388028
                Encrypted:false
                SSDEEP:
                MD5:BA795E8CB404D027CF5C35EBC57AD4D2
                SHA1:2FBE736D386251D6015648A7EF4038EA81D47C85
                SHA-256:250028649DFA41558B7C774E0B155732E0440C00E1A09E783A2D6BB3380833E5
                SHA-512:BEB71D4FCB51B61696B0E36F457B97695F8B186AFCAB6B08DF99EFCCAF45BBCB4110A3DA0522748C04592C7C8154DD156F9F19A6FFEC296B25D02C0A833F86A8
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............................................................J....r.....Rich...........PE..L.....`?...........!.........`............... ......................................................................p....... (..x....P..................P(...p....................................................... ..D............................text...d........................... ..`.rdata....... ... ... ..............@..@.data........@.......@..............@....rsrc........P... ...P..............@..@.reloc.......p.......p..............@..B........................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):260176
                Entropy (8bit):6.551144104973552
                Encrypted:false
                SSDEEP:
                MD5:86EDAC80ADC6B1B006B85CB94CE34BD8
                SHA1:05643EE0AD56B502575E4E3A61BB08181B9E1E99
                SHA-256:DAFB1F18552A63CBFA6F9F79D678AA36B92E71F7AC0D1CAAE56B359E682AEB95
                SHA-512:BFE8E40D84F9113436796328E0B5F842DFF9332A661E05587C18180174B83F8ED7E610FF0A67C250F0858A59D477C178CDAB15E987009120B06C14E1DA567E86
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......z.?.>.Q.>.Q.>.Q.c.[.;.Q.E.].;.Q..._.=.Q...Z.?.Q.\.B.;.Q.>.P.f.Q...[...Q.a.Z.6.Q...W.?.Q...U.=.Q.Rich>.Q.........PE..L......<...........!.........0......E...............................................<...................................Z...X...P....p..P$..............P(.......;......................................................`............................text............................... ..`.rdata..............................@..@.data...$...........................@....rsrc...P$...p...0...`..............@..@.reloc...<.......@..................@..B........................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):256080
                Entropy (8bit):6.638184749491226
                Encrypted:false
                SSDEEP:
                MD5:F5B1B155008B0CFE5A3478BF73BAB385
                SHA1:8A1B07929F2B8B3253E725055DE563F40BA91EBB
                SHA-256:6D659A1D63472F224315CC365E15C493686DDB2F1695C211FACBFDD9A2D0CBD6
                SHA-512:480B5794ABAC3AFC4183FD6BFF0ECB83DE8137A0BD320C193AA72FEF417FFA583492343B1AEC982E54AB23D7B5571D6214D74585400C1A06AFD7AAC139CB424B
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......s..7...7...7...L...2......4..............C..........n..2...7...S......?.....6.....6...Rich7...........................PE..L....Y.:...........!.........`....................h@................................ce..........................................<.......`$..............P(.......8..............................................D.......d............................text...T~.......................... ..`.rdata..S........ ..................@..@.data...p...........................@....rsrc...`$.......0...P..............@..@.reloc...?.......@..................@..BP .: ...P .:-...P .:7...........KERNEL32.dll.NTDLL.DLL.USER32.dll.......................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):178256
                Entropy (8bit):6.141775713026714
                Encrypted:false
                SSDEEP:
                MD5:3E8C0E13F58248542B3CD759A0E44242
                SHA1:FCF4C9DB09F1ED38F7285426BE3B9CDC04E12EB2
                SHA-256:E227908946CCAA418D1E0BCD2B4AEA1041B13E318A6CF96C23AD92369D8CDFA0
                SHA-512:5A9AE3FDA972231858EA31225B74ACB26C954E053FA8F69B3610896984A9CCF2C5E49B460B3B578359D00259D5F2779C8A1F379245128C23E997AEB48CFBDB87
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........./...A...A...A..M...A.c.O...A..J...A..K...A..E...A...A.8.A...@..A..R...A..J...A.'.G...A...E...A.Rich..A.........PE..L.....{:...........!..............................@........................................................................8........0...8..............P(...p.......................................................................................text............................... ..`.rdata...U.......`..................@..@.data...|.... ....... ..............@....rsrc....8...0...@...0..............@..@.reloc.......p... ...p..............@..BP .:H...P .:U...P .:_...P .:j...P .:t....................3m9............KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.ADVAPI32.dll.lcppn201.dll.nNOTES.dll.MSVCRT.dll.............................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):280656
                Entropy (8bit):6.044611695875998
                Encrypted:false
                SSDEEP:
                MD5:575140C93BE1A6B2DBA0551ACC977BA7
                SHA1:B66181A36E5C00A82B5F3C8A2191E27E3D8ED65F
                SHA-256:8D5949A87110E430E8CC55756F41BF83547ED918EB7218DBB6F03A6825CE0933
                SHA-512:456039FAEA1E9BB8209AD028FEB2EED634149AC8F2B8DB5FADBA6347580F04C2D50D303F5E8BF77DFCA12BDA7CA6F7984B972FA8E8B8FAE94E7CA69F40833C59
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........@2+.!\x.!\x.!\x.=Px.!\x.!\x.!\x..Wx.!\x..Vx.!\x.=Rx.!\x..Wx.!\x.!]x. \x.>Ox.!\x..Wx.!\xN'Zx.!\xv.Xx.!\xRich.!\x........................PE..L....:...........!.....p...........=.......................................P..........................................................Ho........... ..P(......l+...................................................................................text....e.......p.................. ..`.rdata...v..........................@..@.data....}.......P..................@....rsrc...Ho.......p...P..............@..@.reloc..,R.......`..................@..B................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):219216
                Entropy (8bit):6.228390953919739
                Encrypted:false
                SSDEEP:
                MD5:044A16F59A71780B5434497C64AE0671
                SHA1:512D24A0D34A92423E35F2ED273697B5EE6D2EC1
                SHA-256:8F8BA32DA6D2A61B9EBAB97F0D8CAF30037B360B999A21C6126088136DF352CD
                SHA-512:F801A9372A94EC7E843E75E51F0BBEC1FE21F613E76DFAB05DA28626834AADBCFAFBF03F366739CB54B942ADFA59F0B2AD01B0D9F208C0B70CACA37206534A5A
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........q.[....................................................q0..........................?............3......I.......q0......Rich............PE..L...4S.=...........!.....0..........}".......@...............................0.......................................l.......U...........a...........0..P(...........................................................@...............................text...# .......0.................. ..`.rdata...7...@...@...@..............@..@.data...X...........................@....rsrc....a.......p..................@..@.reloc..`$.......0..................@..B................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):148048
                Entropy (8bit):5.61603076147496
                Encrypted:false
                SSDEEP:
                MD5:3090A54B6FD000DC205EB691D9543CDC
                SHA1:5EEA72B0F6678C6EEF186769170A579A017BE4AF
                SHA-256:9A0310224E211095D0C2BF270FBA9E542ECDB7A20CBD2F3CCA2069419717E855
                SHA-512:C1196234C4263146F4E77EC79D9E0D1A33036B4451BF0C33DDFA4904613EB8C5F95CDAA72BEDEABA092C94693399D8A7B52173544A5D6D4A0C16C7EB4C6EFC70
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Y.:...........!.................n.............@.........................`......................................p....................>..............P(...P..............................................h.......\................................text............................... ..`.rdata..6...........................@..@.data...X...........................@....idata..............................@..@.rsrc....L.......N..................@..@.reloc..>....P......................@..B. .:P.....};X...P .:e...P .:r...P .:}...U .:....P .:....f..7.....3m9............MPR.dll.COMCTL32.dll.KERNEL32.dll.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.MSVCIRT.dll.MSVCRT.dll.........................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):34896
                Entropy (8bit):4.10729036142961
                Encrypted:false
                SSDEEP:
                MD5:1D24E47D321A5F9B1ED3D639B0294F19
                SHA1:DCA2CA72B36B7FCA494B194FFE4C640D36137B4B
                SHA-256:3790E0302AFA5F324DA7CFF464E3A2AF83642C1AC8BDEEA35017AFFCB5E08483
                SHA-512:28FFE4A8F5F2D87D752877E75288EF4FD482472F19ADF84A4C5A224045072220C39BDD10B754E1A5E95B933ADE6E8873373D6754282C2785F99CFC05A33345E8
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........?...Q...Q...Q.j._...Q...P...Q...B...Q...Z...Q...[...Q...W...Q...U...Q.Rich..Q.................PE..L...L(M8...........!.........@............... .....@.........................`......................................"..6.... ..P....@...............`..P(...P....................................................... ..T............................text............................... ..`.rdata....... ....... ..............@..@.data...L....0.......0..............@....rsrc........@.......@..............@..@.reloc..b....P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):63568
                Entropy (8bit):5.912744901378977
                Encrypted:false
                SSDEEP:
                MD5:ECBF5CDB01882D6E4D448606B8E10B72
                SHA1:E09529343968C5440DCAF5B5DD425E21D164B927
                SHA-256:C37E921030E975517DC643B95971EBC9F0376C1FF876128839DAB085102E8CCA
                SHA-512:6D4207706A065664C9B30AB8A18F431E2592DFEC9287E3FA523672ECCA8FB86C623C4704572CED5CCF9E98591738A5981D6C1102C5D3DB670759F2540E767C05
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........\.Y.=...=...=..Z!...=..&....=...=...=..."...=...!...=.......=.......=...;...=..&....=..Rich.=..........PE..L.....`;...........!.........P.....................................................-......................................h...P.......................P(..............................................................8............................text....x.......................... ..`.rdata..............................@..@.data...............................@....rsrc...............................@..@.reloc..d...........................@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):63568
                Entropy (8bit):5.069283497092632
                Encrypted:false
                SSDEEP:
                MD5:EAB1D836A6176A76B1428746C96908D7
                SHA1:CFC8B2B1EF6134A5FC00ECE00D7717DD284412F3
                SHA-256:152DF2968992464D394CA3F5AB9340126E79BAB4805179284A792FD28B5B6C31
                SHA-512:C15C308F8C9CAAE7821681473808123387499AAB00B261E3939F1C623A0BC5286D15B8E77DCCE5EF01A7E5CC3BCE9E22CAEA969032E134BB14293A88A0120C2F
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......!+..eJ..eJ..eJ...U..dJ...V..qJ...U..]J..eJ..=J...U..gJ..ci..aJ...L..dJ...j..aJ..RicheJ..................PE..L...3.V<...........!.....P...p...............`......................................................................`k......`f..<.......................P(......8....................................................`..,............................text....I.......P.................. ..`.rdata..s....`.......`..............@..@.data....;...p...@...p..............@....rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):38992
                Entropy (8bit):4.812103221979044
                Encrypted:false
                SSDEEP:
                MD5:D5E6E4C3BC87DAA8325E1CA7E3C92D2D
                SHA1:74DDAAA47CAEEB7C6B906016EADA6E474B99A4A4
                SHA-256:1C27F5AD68C2DDCA748245DBD6B51199013E8EC4C87B4A6759361126141C020D
                SHA-512:4DF571AD5031B1316159B522A3AE42EE7DEB1310D60B644F241A41DD06DDBAD3D182C64DFF621166736F13AC24D04C94C698E1E9FC2F93F6C8A4487759E0C44F
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......-...ir..ir..ir...n..hr..ir..Nr...m..lr...R..kr...R..nr...t..hr...R..jr..Richir..................PE..L...L(M8...........!..... ...@.......).......0.....@.........................p......q................................3.......0..P....P...............p..P(...`.......................................................0...............................text............ .................. ..`.rdata..^....0.......0..............@..@.data...,....@.......@..............@....rsrc........P.......P..............@..@.reloc..p....`.......`..............@..B........................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):59472
                Entropy (8bit):6.202859838121697
                Encrypted:false
                SSDEEP:
                MD5:53CAFEF7D35B8CD1A57119C88A7D8A31
                SHA1:0524048198C63CA788EA5FCF96DB73C1E04D8761
                SHA-256:E5753165A854625CA0F71947686AD04ABBF3BB1BB853B5B3ED88E7162229B34E
                SHA-512:A6B33A09CF032814624E72CDE431AF15002B0873610C93CFA5A1429E9AF4BB2AE06F8BD4E3AA0C041B093453111622D3DFFF90AB8307C4BFB85088973B9BCB29
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........<...o...o...o9.o...o9.o...oR.o...o..o...o...o...o..o...o..o...o...o...o..o...oRich...o................PE..L...L(M8...........!.....`...p......y .......p.....@.................................N...............................|..[....v..<.......................P(...........................................................p...............................text...._.......`.................. ..`.rdata..[....p.......p..............@..@.data....<....... ..................@....rsrc...............................@..@.reloc..L...........................@..B........................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):34896
                Entropy (8bit):4.165010768343044
                Encrypted:false
                SSDEEP:
                MD5:291D84ACDF5FC187DB0EC70622C95536
                SHA1:DFDE81D6B43E08ECE9D82322D89446856C55C882
                SHA-256:3862B1288666E34557D7CD6AB7A7A801562960DBB30600C9747E5FC9F5D72E76
                SHA-512:D746ED53B51113CE3379FD6630E0077648119D4B967DFEF34A9DF0A864184AFB0BE84288B98E1185FB724F9535B922B59FC6D23A2B5D61DE7C358F7AEFC645EF
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......-...ir..ir..ir...n..hr..ir..Nr...m..lr...R..kr...R..nr...t..hr...R..jr..Richir..................PE..L...L(M8...........!.........@............... .....@.........................`......................................."......h ..P....@..(............`..P(...P....................................................... ..h............................text...~........................... ..`.rdata....... ....... ..............@..@.data........0.......0..............@....rsrc...(....@.......@..............@..@.reloc.......P.......P..............@..B........................................................................................................................................................................................................................................................................................................................................
                Process:C:\ResaApps\ResaLauncher.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):27
                Entropy (8bit):3.7225059102772766
                Encrypted:false
                SSDEEP:
                MD5:F6266207953D0C31150114602E557F8C
                SHA1:47FEC6C4D4A5E9C6E94C7E8C95541042D008E438
                SHA-256:08D55B66CA64D642F01FAD2A3F822A3470B8344E71B55C728E5A1D43F9DE58C3
                SHA-512:5982AABD449C33DE70BF6810EFF4887BC3B64F0BDF65C822257405E04BC00F5AA2C409DF7800F385352003491032FF23B2A2347FF53A7BCBF3C8CF389BE62FEA
                Malicious:false
                Reputation:unknown
                Preview:..[AppOptions]..LEA=?????..
                Process:C:\Windows\System32\msiexec.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Archive, ctime=Tue Mar 12 14:30:33 2024, mtime=Wed May 29 15:30:39 2024, atime=Tue Mar 12 14:30:33 2024, length=10988624, window=hide
                Category:dropped
                Size (bytes):729
                Entropy (8bit):4.616365233120022
                Encrypted:false
                SSDEEP:
                MD5:AF76291D2021ED953316D3CD5DCCC5FD
                SHA1:F609DC86F6D9577AED9031966BCDB590136E7C11
                SHA-256:44335E5CAB9CB3A425B70F87CEE04DB3FAC17255B7B46246294DBBFEB187301C
                SHA-512:A964471AD46FA16F30288D99539CDDAAA3611A2C10549E9908F5F7CA06608BF4768F978B3345226FDE987205BFAB7ED2CCABD11B440FFB9064A4F1F3061EF208
                Malicious:false
                Reputation:unknown
                Preview:L..................F.... ...y.E9.t........y.E9.t..P............................P.O. .:i.....+00.../C:\...................Z.1......X...ResaApps..B......X..X............................%I.R.e.s.a.A.p.p.s.....n.2.P...lX.{ .RESALA~1.EXE..R......lX.{.X.....[......................)A.R.e.s.a.L.a.u.n.c.h.e.r...e.x.e.......K...............-.......J...........I.d......C:\ResaApps\ResaLauncher.exe.. .W.a.y.n.e. .R.E.S.A. .S.M.A.R.T. .m.o.d.u.l.e. .l.a.u.n.c.h.e.r.".....\.....\.....\.R.e.s.a.A.p.p.s.\.R.e.s.a.L.a.u.n.c.h.e.r...e.x.e...C.:.\.R.e.s.a.A.p.p.s.`.......X.......760639...........hT..CrF.f4... ....F...../....%..hT..CrF.f4... ....F...../....%.E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):174080
                Entropy (8bit):6.279217790646268
                Encrypted:false
                SSDEEP:
                MD5:31CAD6A3EDD1C32981AD6B565CBEAC94
                SHA1:9338978C85A9423EE2A38CBA027F79192D684F1B
                SHA-256:B8521ABDA09EC17DDAD36528C1BC50395DC8C5F7C11C026A5B3FF23110C54182
                SHA-512:02E198B8EF192DE55DB35AE00A16A80B3309A9373A596C20D617B43DD7159A635BC303F371859E704375521A1242D02754807E2E9DFEF63FFD06993B24C17D3D
                Malicious:false
                Antivirus:
                • Antivirus: ReversingLabs, Detection: 0%
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......D..P....................6...>..............._...........6...P...o.^.....o.j....................Rich............................PE..L....S.L...........!........................................................@.......................................@.......9..P...............................@.......................................................,............................text............................... ..`.rdata...@.......B..................@..@.data.......P...4...4..............@....sxdata..............h..............@....rsrc................j..............@..@.reloc...%.......&..................@..B................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):161850
                Entropy (8bit):4.662047306059787
                Encrypted:false
                SSDEEP:
                MD5:6D2EA67B5892DC26D5ABD01608BC086A
                SHA1:14BC24724509E44918252D155FA3E7152FE232F3
                SHA-256:76AA59963903F0299CDA780A1DA7583227CB4C84F4EFF213A101841CE02C39C7
                SHA-512:1842D801325A1FD6F479A42A98A1C5A49EE7707B682E45BC95AE23C0E073288E9C4889710F6D925B6E852540355CB66565E2B745CFA7C76F34BF26FDDAAD9D7E
                Malicious:false
                Reputation:unknown
                Preview:Please install the common controls update from Microsoft before attempting to install this product...Setup resource not found..Setup resource decompression failure..Setup database not found..Runtime error in install: ..bytes..KB..MB..Attempting to get value of undefined variable ..Attempting to set value of undefined variable ..Copying: ..Unable to copy installation data to local folders..Downloading Web Media: ..Unable to download installation data from the web..Extracting Web Media: ..Unable to extract installation data downloaded from the web..Please locate your original setup sources to continue operation..Original setup sources required to complete operation, sources not found..General setup failure..Runtime error in setup script:..% complete..bytes received..InstallAware Wizard..InstallAware is preparing the InstallAware Wizard which will install this application. Please wait...Retry Download?..Downloading of installation data from the web has failed. Would you like to try again?
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (343), with CRLF line terminators
                Category:dropped
                Size (bytes):116680
                Entropy (8bit):5.881929868312602
                Encrypted:false
                SSDEEP:
                MD5:D1A05252BF432D9E07828619FDAEE662
                SHA1:8286F60352B7CB95AB4F03FF11C0970A39178DC1
                SHA-256:37C69CDBBD5E6A7B5ECF8795DEA7504075C008C58CDAAD54CAECAA75C215B82D
                SHA-512:45793D6E99D1111810A25BA5BA90DD39E699360978B71E16E04E3EFF4A8D73B930945B59BCA71B13F195964A1F20DB9D4D1FA1B4402C2618403EAB93B7FBE612
                Malicious:false
                Reputation:unknown
                Preview:.Comment..Comment..Code Folding Region..Code Folding Region..Comment..Code Folding Region..Comment..Code Folding Region..Comment..Set Variable..Set Variable..Comment..If..Set Variable..Set Variable..End..Comment..Code Folding Region..Comment..Code Folding Region..Comment..If..Comment..If..Terminate Install..End..Comment..Comment..If..Set Variable..Set Variable..(Un)Install MSI Setup..If..MessageBox..Terminate Install..End..If..MessageBox..If..Reboot and Resume..Else..Terminate Install..End..End..Set Variable..End..Comment..Hide Dialog..End..Code Folding Region..Comment..Code Folding Region..Comment..Code Folding Region..Comment..Comment..Comment..Get System Settings..Get Folder Location..Get Folder Location..Get Folder Location..Get Folder Location..Get Folder Location..If..Set Variable..End..Get Folder Location..Get Folder Location..Get Folder Location..Get Folder Location..Get Folder Location..Code Folding Region..Comment..Code Folding Region..If..GoTo Label..Else..Comment..Comment
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):409600
                Entropy (8bit):6.561940600430892
                Encrypted:false
                SSDEEP:
                MD5:3F3B36212413A45A6A84DC8A2EEBBEE2
                SHA1:F3F6CEE864DEC7000B4378A474DDFB4506ED7D97
                SHA-256:401F13E737C13F627757FAD1CB6E256135F480E478C9D1BD085A58123456F9EF
                SHA-512:E522B6682578EABB5F8299D60E0E6B1C74C116954C46C392EE839D6CE77D6C476E8973C8194C3D1D1A1765C6CEE417B715CBF7295CA664462824127DC2222010
                Malicious:false
                Antivirus:
                • Antivirus: ReversingLabs, Detection: 6%
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....X.................`..........$w............@.................................................................. ..Z........$.......>...................0...X...................................................................................text....V.......X.................. ..`.itext.......p.......\.............. ..`.data................d..............@....bss.....L...............................idata...$.......&..................@....edata..Z.... ......................@..@.reloc...X...0...Z..................@..B.rsrc....>.......>..................@..@.....................@..............@..@........................................................................................................................................
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):11705
                Entropy (8bit):7.788035238778996
                Encrypted:false
                SSDEEP:
                MD5:0354881E1ECD1EFCDF57157CFBDB4F94
                SHA1:F7DC317D0B7A92EDAA2ADE693F9552886BE284D0
                SHA-256:E66906AE14698BA433A81E136E1AFF974A188CDAF6FA4DBDAE47B1EB185B1D5B
                SHA-512:D4916AFDE2AA828A94A1213E1DD51510B39C66A79DEC2436EE5CC47DB593AC87106EABDFCAC7E6E209C8CAACF88D4346D4EAD48F3F71FC8D63368C578281E842
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..-..TPF0.TfrmDesign.Features.Left....Top.b.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &..
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):14804
                Entropy (8bit):7.817275683668764
                Encrypted:false
                SSDEEP:
                MD5:69E965AB6133576153A0951756126F77
                SHA1:40B4137695FAB2FA7631D31A0CEABA8F819D5C76
                SHA-256:19A462F2CC8B9D38CE6DD459CEF9297F55B3FE90540326259315DC940737364B
                SHA-512:AE5850E76190C7E79F7FE3807CC65D26DA2B586157DC9F15A2FF365D4510525D6CEFF05B18E0AB67FD7DFFA9CE34204108FE3E55E5111E59443A6387CCA0C4EB
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..9..TPF0.TfrmDesign.Features.Left....Top.k.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.DoubleBuffered..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...GlassFrame.Top.".OldCreateOrder..Position..poDesigned.Touch.ParentTabletOptions..Touch.TabletOptions..toPressAndHold.toPenTapFeedback.toPenBarrelFeedback.toFlicks.toFlickFallbackKeys..PixelsPerInch.`.TextHeight....TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:Unicode text, UTF-8 text, with no line terminators
                Category:dropped
                Size (bytes):3
                Entropy (8bit):1.584962500721156
                Encrypted:false
                SSDEEP:
                MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
                SHA1:57218C316B6921E2CD61027A2387EDC31A2D9471
                SHA-256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
                SHA-512:37C783B80B1D458B89E712C2DFE2777050EFF0AEFC9F6D8BEEDEE77807D9AEB2E27D14815CF4F0229B1D36C186BB5F2B5EF55E632B108CC41E9FB964C39B42A5
                Malicious:false
                Reputation:unknown
                Preview:.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):17243
                Entropy (8bit):7.843416653790886
                Encrypted:false
                SSDEEP:
                MD5:96219B651C649C6C2E6F6879347AEACF
                SHA1:8C2B34CAF357E2948A479F3C53AB6BE2B904A361
                SHA-256:EA86DC94C1EF8FC6ED57228E1304C92521E715FE74E911CB3EEC633624F0CED2
                SHA-512:F7F13426917193FD7786D49BE2DB3A350F485DAFE8BC277C0338D745E4AF97FF5A1BC43A823F35A431E2720905C77D674CEA6F7C532E9B1750CDE744946E7BCF
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.GC..TPF0.TfrmDesign.frmDesign.Left....Top.X.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):1561
                Entropy (8bit):5.018115004625162
                Encrypted:false
                SSDEEP:
                MD5:2FE4E500443ECB1E27A767BEE9A18C63
                SHA1:887A5789CDAC46BEA2829870DF02AD6B87A92270
                SHA-256:6492FEB41031C64C70FA8FABAABCCDE4846F9438B017D152C68C4B356C6A167A
                SHA-512:9475EB0E7509493A23DEA491CFA0A9A1DB0D339C216F1E38512DF18A74D80C69B6C8CE9C10131047227FFA3E979D5D6F144748569CFD9209C47977D770D94DD4
                Malicious:false
                Reputation:unknown
                Preview:IF (checkSuccess.Caption = COMPLETE) THEN textComplete.Visible := True;..IF (checkSuccess.Caption = REBOOT) THEN textReboot.Visible := True;..IF (checkSuccess.Caption = CANCEL) THEN textCancelled.Visible := True;..IF (checkSuccess.Caption = ERROR) THEN textError.Visible := True;..IF (checkSuccess.Caption = COMPLETE) THEN RunNow.Visible := True;..IF (checkRemove.Caption = TRUE) THEN textRemove.Visible := True;..IF (checkSuccess.Caption = REBOOT) THEN RebootNow.Visible := True;..IF (checkSuccess.Caption <> COMPLETE) THEN textComplete.Visible := False;..IF (checkSuccess.Caption <> REBOOT) THEN textReboot.Visible := False;..IF (checkSuccess.Caption <> CANCEL) THEN textCancelled.Visible := False;..IF (checkSuccess.Caption <> ERROR) THEN textError.Visible := False;..IF (checkSuccess.Caption <> COMPLETE) THEN RunNow.Visible := False;..IF (checkRemove.Caption <> TRUE) THEN textRemove.Visible := False;..IF (checkRemove.Caption = TRUE) THEN textComplete.Visible := Fal
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                Category:dropped
                Size (bytes):1597
                Entropy (8bit):7.871063017224323
                Encrypted:false
                SSDEEP:
                MD5:B7225A16DAF9DE1D514AEFE567FDF2F5
                SHA1:D6A00C526C425FCD5EF49B0C87814F2CF476CB59
                SHA-256:0E2DEFC9B470D3F9BD184D254493EFAD94EA0273C1FE17FC8FC651D47B01734E
                SHA-512:31412603AE87F2B9C9DAD2D0BA64868105586D1778846DE5F1C14667C4292DE36FC193B54670BDF130019B0B42AB59EEF2C2D8672226BA755181FEA894BD9246
                Malicious:false
                Reputation:unknown
                Preview:.PNG........IHDR... ... .....szz.....IDATx.W.L.W...!..dl.'.@.10.a.....2.T'.....SD..-PK@t.....:53.... :#F.......|"...L....6 m)Lw........9...K.+.b...z.x........=...J.V....n3[.B..v[m..../....o0.L....Q...&...$~?%%?PG..S<..]...$.Z......O.3".k....m]..2S9..4,.k+.xf..k.F...V..4[Ec'K.2.2..PK.....H$..H.....kA...M..>.zs.....^.*..K"...j..:..Hu.T..Q.....N...y'.+9.dR.{..Xn....w.f...R.KQB.]z........6>..,.......q.%........;.,......U{.i....Z.....)._I..7..J.q..d)...CM....;...,R~.B.S...E...p[-O........].F...%..A.%....{.%.*...]Q..>.-..f..C..i.Q..+5.......A'~.....J...M.mtN..0..r.>.@K.....D...<...CI^#.-.P.}?R..M.-.7..GS...Z^9s..<6.....>......<..g.~.9....{]Ju..}`..Z(..ikw^.,)X..g...|G.LQ9A^...9pe....7d.......SE.Q..../nx.}_..F...$..I..K...o4.^ ..e.X.Q.H......&........Q..............\n....J......./...7.....E.9.....$...K..!...c.`.=.Jd.nq.n.W.Q...Q.#s.w._.d....u...Q].-U.N.J..&.O..=......a+.k.....%.$..(.....@`...lx.......tDC..=.{...^"...@.....\{;#.^...G.q./AA.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):15539
                Entropy (8bit):7.882108328554239
                Encrypted:false
                SSDEEP:
                MD5:D628C74997624EBF0A80646FFB44E28F
                SHA1:4C5E9B438CB369B636585A0C2018B6AC45894E28
                SHA-256:5DBDB0E718CECA0DC560A95B34660E8E0F5805F21A457B444BA08E10F21CAB7C
                SHA-512:14906D29BF088FE72D2403DE21AE3DF6B3FFFD150749C0E409642F09927EB0BAB40B2EE951817EEF6B9982249C852E1833F32C7D078230BDFC8B76B188913599
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..<..TPF0.TfrmDesign.frmDesign.Left....Top.;.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):134
                Entropy (8bit):4.972941220095657
                Encrypted:false
                SSDEEP:
                MD5:FDE0C4E52D8AAE629E67739E73DC1101
                SHA1:0634DAE366F408FB43D67C4D0F41BE5082CB446C
                SHA-256:FA082D1A986C183D474DB7867058CA1319EE07ADB7AA131EC6A65ED7E2446118
                SHA-512:3C9B279DA6BF20B20541A8DA67A22BBB7EC155634C5307F2CC14133F137A9919B858C72B615FC688C93CA321C8763715E36E831769D93266DFDED4EB35353D8E
                Malicious:false
                Reputation:unknown
                Preview:IF (License.MaxLength <> 2147483647) THEN Next.Enabled := False;..IF (License.MaxLength = 2147483647) THEN Next.Enabled := True;..
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):1478432
                Entropy (8bit):6.658159851533953
                Encrypted:false
                SSDEEP:
                MD5:83F7C4CC2A88AF7650D1AAAD2522038C
                SHA1:D6F2B52EA0E912F0F23FD2A7BC0BB4A40EC8558B
                SHA-256:6FD1E5690675F7EC8CF2807DFEB47B2E2DC046ADC7152AD884B8AE6774DC818E
                SHA-512:F6EEB1FFA955CDEFAACCC6AFF0867EBF2ED39F4F9B14910B77180416D37EDF7C9F6D03BAEF1662206FAFD9316632F49F6353FDF6143CB6EEFA962338CEE9D035
                Malicious:false
                Antivirus:
                • Antivirus: ReversingLabs, Detection: 0%
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....T:b.................t..........(..............Q....................................................................R....`..*6.......`...........8.. W...........................................................j..`.......^....................text...@].......^.................. ..`.itext.......p.......b.............. ..`.data...$i.......j...x..............@....bss.... T...............................idata..*6...`...8..................@....didata.^...........................@....edata..R............$..............@..@.rdata...............&..............@..@.reloc...............(..............@..B.rsrc....`.......`..................@..@.....................8..............@..@........................................................
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):1390160
                Entropy (8bit):6.681501050233468
                Encrypted:false
                SSDEEP:
                MD5:180A2F94571C9D020316F64FA4037286
                SHA1:81FDA4CD7FD97E30425BBD6B967EC8578E1DD5B9
                SHA-256:97EB0AE031A75175482ED58DBB279E086D5AC93B312139D7194F2DE901B2587C
                SHA-512:7E958B8DC0DE436E897A54FC8D3094256551E694A87F71107EFAB73EF7ECAF07D39CF890BDCC6ABB22F30512AF475F0F74B67A4D19D5A5C0B8D457A0106C101B
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...uT:b.................~.........................Q....................................................................O....P..@=...`...Z..............P(..........................................................d[..\............................text....i.......j.................. ..`.itext...............n.............. ..`.data....O.......P..................@....bss....(T...............................idata..@=...P...>..................@....didata.............................@....edata..O...........................@..@.rdata..............................@..@.reloc..............................@..B.rsrc....Z...`...Z..................@..@....................................@..@........................................................
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):1341520
                Entropy (8bit):6.660112413632557
                Encrypted:false
                SSDEEP:
                MD5:D8C06B605B681B1FE285D9D15AB4C8DB
                SHA1:5683E351A797FE92F2D94672D52B29CA26400693
                SHA-256:0702A622559C87C3D7EDC365080A82A8E1605F85B7A9922C1D2710965C9AC81A
                SHA-512:EC03C912CA2FB08528D64401B51BCF1BA5B0231B8DE611D15F88357EACF13871F7EC00795866BBF0C967D4C80C8E7826198932AF5002634A88462F8A83DDED2A
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...lT:b.....................v.....................Q................................d...................................R......."6.......Z...........P..P(... .........................................................\.......^....................text...H........................... ..`.itext.............................. ..`.data....O.......P..................@....bss....|S...P.......*...................idata.."6.......8...*..............@....didata.^............b..............@....edata..R............l..............@..@.rdata...............n..............@..@.reloc...... .......p..............@..B.rsrc....Z.......Z..................@..@.....................P..............@..@........................................................
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):13680
                Entropy (8bit):7.836566536384282
                Encrypted:false
                SSDEEP:
                MD5:285F90867436E3264B622C8F553C9969
                SHA1:3AAC56182756F5F7F4BFAABF9C7D98CAB1DD5CBD
                SHA-256:38C7BDC7BF25B83B781DA8A9C76F0D37CFE6552CDACCC2D930397C982FF7FDC0
                SHA-512:946C427991D14647E632AA70046E6BDE81F4496625D1383CEEE520765DD21DCA0A8E42EB4BBE01C5699E62BC8FB803C315A3060FAAA086C9FFB6F634559AC93E
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.\5..TPF0.TfrmDesign.frmDesign.Left....Top.|.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):15992
                Entropy (8bit):7.900449132476884
                Encrypted:false
                SSDEEP:
                MD5:BD05A55D045248468FB8D49C46AA5646
                SHA1:E2385F8A753849CA2BD18D7ABE411563C2D926D9
                SHA-256:11585CD1BCFCF0DD05029A4BAF371CC066A601E86C77ED917A2592D2AE412B16
                SHA-512:0D6C1667CCBB87C5F9200C84F1027CAAB4E5470A04848E82C91D4DE34F06AC3C9E71B3701F325DF2793760811B20915300579E5D9ACBEDC00AC499BB68ECD890
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.d>..TPF0.TfrmDesign.frmDesign.Left....Top.`.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):18397
                Entropy (8bit):7.885680025219992
                Encrypted:false
                SSDEEP:
                MD5:2823202C1BF8F7CDAA54954F2752CEA2
                SHA1:74A8BF1596CE14FFE9644FC22AECDDAF9DEF39B3
                SHA-256:738896095674CB6D55C55949745A84E9930D59AFDD1E80CEC3863A12AD555B31
                SHA-512:4A7399684329FA996BA4520D6A94D91F26ECE7FAAE7A64186310C86356A4812A4C21D059E9FBA3EFA90B1E6DC35721E650C9FB33ECDC74DB74AA3B53F39636F6
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..G..TPF0.TfrmDesign.frmDesign.Left....Top.f.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TShape.Shape1.Left.(.Top.`.Width.)..Height.a.Pen.Color........TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V....
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):19604
                Entropy (8bit):7.894207202763479
                Encrypted:false
                SSDEEP:
                MD5:35B5EC8E5725D4B9EEE2C4B2FD5C423E
                SHA1:56B5A37B6FAF57FA2366AFD2734400A8B66068DC
                SHA-256:1CDA7F01A1925E69AA54057F8BE2D6E114604A038A26E9292755D64B743242FA
                SHA-512:676C54709C081DC5B9288C99530D0B26310C14A06674E39424A27CF450A26C721400B1E887F08D448B48900C57917AD812D26F9FABD8E477996BBFE057021073
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..L..TPF0.TfrmDesign.frmDesign.Left....Top.^.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TShape.Shape1.Left.(.Top.`.Width.)..Height.a.Pen.Color........TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V....
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):16170
                Entropy (8bit):7.889388739341066
                Encrypted:false
                SSDEEP:
                MD5:C3B5A987A157EE65C45362455CF38B4E
                SHA1:ACDC93B6D8E8E8ABA958D2BBDC579216DD8C631B
                SHA-256:C7B4ECC8FC7574B8CABFE688EEECADF3DBA5CE26877E73E78C9333BE07EBFF32
                SHA-512:25F591204085E1F4802BEA5918F1DC5F5E593FB5542EE7E96F525D1FCDDEAA64E627A238FC65B940BD7C6F9621D3D1415A3D8D1E95150A7F55F0703E5BF588EC
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..?..TPF0.TfrmDesign.frmDesign.Left....Top. .HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):16171
                Entropy (8bit):7.887407979431327
                Encrypted:false
                SSDEEP:
                MD5:72BBB88B1AB45366EDD1BF68FD678C01
                SHA1:0F12868F73CFD8A9334F78F300FC9185BBA067FC
                SHA-256:9EF6BB3720702F047701C09E184C99F70C9A2613EF01C5BBF825A40FE18AD932
                SHA-512:306A8890CD244C57D241C3DE4672483ECA30D3390C5B1134953D94C51C7B2463189E073CEBC73247BAC34D54807072EF2A5D3EE204DBF247C1C52DD684E19C41
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..?..TPF0.TfrmDesign.frmDesign.Left....Top.E.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):218
                Entropy (8bit):4.635426120490109
                Encrypted:false
                SSDEEP:
                MD5:188D78E86F52BF3F82BC567339268E81
                SHA1:949ED916F5A813020D40C068EE24E010701B73F6
                SHA-256:4E5EE72B6F00571F0CEB8F8C51519E68B4B597E7DC4E4BD7BFF0CC38807EBEF8
                SHA-512:7876002FEB629D9E8DADE3B04321EE8796B979D36B7199CC99B8A8D402C599DCFC970FDD2B7287FC921814F1EADF374E915D66C170075DE3B372C40A7D68FC6A
                Malicious:false
                Reputation:unknown
                Preview:IF (UserName.Text <> ) THEN Next.Enabled := True;..IF (UserCompany.Text <> ) THEN Next.Enabled := True;..IF (UserName.Text = ) THEN Next.Enabled := False;..IF (UserCompany.Text = ) THEN Next.Enabled := False;..
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):16481
                Entropy (8bit):7.847912533314531
                Encrypted:false
                SSDEEP:
                MD5:148D19ACB1248B9B7075FA6830E702D4
                SHA1:093BAC26C070DEA9E1CF8497283E484FE2801381
                SHA-256:4FEABA554177135DF891CD420920EE42551399F4BD99AB6E4AEF11E41D5CE47D
                SHA-512:305AB7A692433DDD02E2898FB5AE4CB441743B39861B55EE519429DBFE58B030D7E3C1B0D0032B0904EA1FDB610E2F84533EEDFC8A06DE9F1BA59EF9808407B4
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.M@..TPF0.TfrmDesign.frmDesign.Left....Top.c.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):722
                Entropy (8bit):4.629672896174913
                Encrypted:false
                SSDEEP:
                MD5:5D78380EBDAD86764F26B73474DF4900
                SHA1:D2574CD9FB599E81C6099738D9D7974CE4039AFD
                SHA-256:DAA5742D80E19668753D435DA0937A4409D22AF73FBAF9DF22EC4CBC34FF5D45
                SHA-512:3533A9D8F4B1D8BD703856B150B8CBA99CA8CF55EF2182EB7B7326BF742C2B4B5CEA896B818FB690E0678689A8B452F22F5F548124D0B8302D776E8B2335B26D
                Malicious:false
                Reputation:unknown
                Preview:IF (Name.Text <> ) THEN Next.Enabled := True;..IF (Company.Text <> ) THEN Next.Enabled := True;..IF (Serial1.Text <> ) THEN Next.Enabled := True;..IF (Serial2.Text <> ) THEN Next.Enabled := True;..IF (Serial3.Text <> ) THEN Next.Enabled := True;..IF (Serial4.Text <> ) THEN Next.Enabled := True;..IF (Serial5.Text <> ) THEN Next.Enabled := True;..IF (Name.Text = ) THEN Next.Enabled := False;..IF (Company.Text = ) THEN Next.Enabled := False;..IF (Serial1.Text = ) THEN Next.Enabled := False;..IF (Serial2.Text = ) THEN Next.Enabled := False;..IF (Serial3.Text = ) THEN Next.Enabled := False;..IF (Serial4.Text = ) THEN Next.Enabled := False;..IF (Serial5.Text = ) THEN Next.Enabled := False;..
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Template: Intel;1033, Revision Number: {FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}, Number of Words: 0, Number of Pages: 200, Title: Resa Launcher Install, Subject: Resa LauncherInstall Installation, Keywords: Installer, MSI, Database, Author: Wayne RESA, Comments: All rights reserved, Name of Creating Application: InstallAware, Security: 0
                Category:dropped
                Size (bytes):798720
                Entropy (8bit):6.223938740758039
                Encrypted:false
                SSDEEP:
                MD5:367DDBF2A55703F967F33DF8D3297B50
                SHA1:876D505A57D7C95876B757C2392A4C95222857EA
                SHA-256:D4AA0247D92E3E628ABA84373669C9DE69DB54A02193CD9546E2C73F3E5FA5A5
                SHA-512:7C8018A447FA9F7D1DEA21F0FECF18C1EEA92A673B2A6C4ECCD6FA7C4EFC371D8A54F543A184BD90728594DDACD9FA1023150E98C364203716B339D730580B4D
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):24419
                Entropy (8bit):7.9088087550032204
                Encrypted:false
                SSDEEP:
                MD5:ED7FFD3D2E03D466C24505D117C3ED6C
                SHA1:9614345913104B664507F7F9DE83BFA7750B79E2
                SHA-256:9065A86FDF3E553BAAD7B79623E889858D1780D4226BEEF0BBD127BCC04EC274
                SHA-512:B5534D3F7A9FEBCF06446F9897BFD2DD901A7D4D71B1A678B5C0CB78A14A6AC0AE394DFAAC851C8CA6268CA6C49D4E1FCD2101617FB23D61F8CFE51731C8BB02
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.O_..TPF0.TfrmDesign.frmDesign.Left....Top.|.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):370
                Entropy (8bit):4.832039103681283
                Encrypted:false
                SSDEEP:
                MD5:38C404F79FA570B4C3B3CC20EE619EA8
                SHA1:607568FFEEFB96E166181261B548A150D8CD6A4D
                SHA-256:543F97888AD39B83984161CBBD1D43C4A846D89D2508132DA97D767DF143FD67
                SHA-512:9AABE8B60D693B11BE74B13BDF9157136E8AE58A75555E2A6DADBDB6BFA55ABE17CC9CE9F793F8F6A86F1F4F9B239721A170DD71C7E675DFBC78AAFF10B302AD
                Malicious:false
                Reputation:unknown
                Preview:IF (Minimum.Checked <> False) THEN Least.Visible := True;..IF (Personalized.Checked <> False) THEN Some.Visible := True;..IF (Complete.Checked = True) THEN All.Visible := True;..IF (Minimum.Checked = False) THEN Least.Visible := False;..IF (Personalized.Checked = False) THEN Some.Visible := False;..IF (Complete.Checked <> True) THEN All.Visible := False;..
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):15960
                Entropy (8bit):7.90133258108296
                Encrypted:false
                SSDEEP:
                MD5:3CA50BAF4AF3620A0919E316013C4FAF
                SHA1:6823D6DFD03FB9D15787B8E77FD650FAD516B042
                SHA-256:9935E6045765FEA14A5E0DE21D8B863AC7BAF16A28E93B9641801722438C0A31
                SHA-512:D07F738A14909F87F80DB8818898008A60E7C73D40CA3E63A4686D919C22CF38FBDAB438E81DE321825478069360ECD511E81C283BF2A2F40D8F30A517DEC831
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.D>..TPF0.TfrmDesign.frmDesign.Left....Top.j.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):14875
                Entropy (8bit):7.865461642184429
                Encrypted:false
                SSDEEP:
                MD5:51EB295880137714775C4EF77B29BB28
                SHA1:62AD2BC7C927D2EA0F0EAB17152F75AB94AA3309
                SHA-256:1B4ABF4C813942C92B2BC235B4BCC55700B0C3A7BEC36C8626FDC73FB79D32DD
                SHA-512:E49970CE953E9FE17D7DF5A3C5EF8428038FE9E129D9EB385D3227742C9C6BA1B9660467CE9B998B22AC3C9E3D7A1C0D36F8AB9BCFAE8D6DFD31901CA590DC36
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..:..TPF0.TfrmDesign.frmDesign.Left....Top.p.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):13063
                Entropy (8bit):7.8744146600743266
                Encrypted:false
                SSDEEP:
                MD5:5FC27F22C0A475CC31A079C12CC0B696
                SHA1:ED297ABD346E8D3D9E652DACB24574C6D25784BD
                SHA-256:DE42B4F72280453D2EFE3A6CF54C8850E178CEFAEABE05BE82921974A0481F8A
                SHA-512:5E48870BA6372CB4380EBAD3A2F511BD462D07018C68F95088AC17E5EF2AFF4C1811CE6F71DE8CB96ED0BA6684B17F5EC09F062DC9F559EE3A25548409D4B66F
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..2..TPF0.TfrmDesign.frmDesign.Left....Top.|.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):13006
                Entropy (8bit):7.87699477550627
                Encrypted:false
                SSDEEP:
                MD5:2C3C9843D9CE9DCE13988E221A95CE57
                SHA1:6006718511D7B34D17E403F829A985142040FCAF
                SHA-256:86A4BF8CB055279D05FDEA72BFE48EC330EB430B8F1BC54A2C63EF28DBF540C6
                SHA-512:8428ED46957B7C0F14CE5F2BF7EB6BD716D65773FA63589F909E22FE91BE43978A49818AC4D8683D35017AF8A9C4A1AD7AF0315BAAE92DDD7D3D4B7803EDB59D
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..2..TPF0.TfrmDesign.frmDesign.Left....Top.|.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$ Setup.ClientHeight....ClientWidth.d..Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Segoe UI.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Top."..TAeroPngImage.AeroPngImage1.Left.#.Top...Width...Height...PngImage.Data......PNG........IHDR................a...PIDATx.cd .h8.3Hh.2..2.Y..8...Fl..".....#..4V.f.nh;.Wd.......%.G..U.o1.H...ka.*..l.......i.....28.1......!U-...-.C.8...2...>...P;i..G.X..f.d..3.......l@...Q.......la`.0e&.E-;....l.{....ch.*Q[..;..,|...`.z..........~q.!..........0.lzP.-...<..)/.?...,...>w.j.#:.P)p.l....8..v>^/+.....K.MDb@L..z._.Kg...\&....V....d.F03j...V:.N.,.0.s.LE...k..d.....3001A..~f.Pi..bVT..F..h.vf.i.f.V.....+..u;$ph.d].....kY.......:...`..x....h!........>.0..X3.z.. &.
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):33309
                Entropy (8bit):3.3772470427001995
                Encrypted:false
                SSDEEP:
                MD5:F1BA2D0A20CF4290FCDB45B3CF54840C
                SHA1:EC808EBC2563D3D00866BDE0AFF4059C3C995C03
                SHA-256:F27A9B4D468632780547E3FC26A59993B3108A18CB096852A302577BFA4C6F2F
                SHA-512:C4073CE6F58447B858901389D52BD479C888370CD6328499B516B9C919A728C4099F00DFA19005AC65BC986A79FF2A9A0E4CAAE9BCC0A5E3A72747696B4BC126
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.....TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................).....!..!..$..&..(..*..-..<..1..4..7..;...Z...j...l...m...v...y...~...~..A..F..F..M..I..M..P..Q..T..[..]..X..m..d..w...}..r..a..n..m...Z..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Revision Number: {34298CBE-CEDC-4FE1-85C1-841B00345C2F}, Number of Pages: 200, Title: Crystal 8.5 for W11, Subject: Crystal 8.5 for W11 Installation, Keywords: Installer, MSI, Database, Author: My Company, Comments: All rights reserved, Name of Creating Application: InstallAware, Security: 0, Template: Intel;1033, Number of Words: 8
                Category:dropped
                Size (bytes):843776
                Entropy (8bit):6.289041745047667
                Encrypted:false
                SSDEEP:
                MD5:A76E7959A85F8A008F3A3D1E2B8A49A9
                SHA1:9BAF03CDB46180DF901B4781CE217883DFF989C7
                SHA-256:EA820BD28294E1B07A8C6B70A03573F60E62229ABFF2B5C48416F406B03984DF
                SHA-512:B317EE84DC55579DE7D74791C0A0719BC15E9EE5B58889AE4137E5A42B51AC5E9435FF34CB8998FD9EA0ADF7AF9F55DE99058AA44A2E9F4604AADAF2173AE7F8
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):33184
                Entropy (8bit):3.358519824453405
                Encrypted:false
                SSDEEP:
                MD5:C92448DB4098F4A3095C0BF94500D2D6
                SHA1:D5F0AAA3C7E55B085D0D57C13499E07AF30354CF
                SHA-256:799B7F02BA036F90052545DA51D2807A0CB65B657C36FB26113BDE086E40D929
                SHA-512:830244E76DBD3CE333A540FB54470F99FC295FCF00CF2D2586FA28094B1A2EB0A5B98EAFBD82A78AD37635E5424FA84C428630B5D42E322E885A846CF0EEE5EE
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.....TPF0.TfrmDesign.frmDesign.Left....Top.|.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................).....!..!..$..&..(..*..-..<..1..4..7..;...Z...j...l...m...v...y...~...~..A..F..F..M..I..M..P..Q..T..[..]..X..m..d..w...}..r..a..n..m...Z...
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):374
                Entropy (8bit):4.773773154848379
                Encrypted:false
                SSDEEP:
                MD5:8101E0CC3186C05F85B2CD484D26AE9D
                SHA1:B3CF33E0784E3A6F3B3FEB2B2501E0BDA5932EFA
                SHA-256:A0E750466327E92E2DCC96D72A19A7738A65AB765262DF4801E6677528F14D6C
                SHA-512:DF3692D29CDF0434806A0BCF034AFE6869B0BF5C0BE24F18637D373374C1E1803AC5B6D1F671CCD6E89B313E26F85657EA487A2EBAEAE0B99359A66F21DF910B
                Malicious:false
                Reputation:unknown
                Preview:IF (Glass.Caption <> TRUE) THEN Separator.Visible := True;..IF (Glass.Caption <> TRUE) THEN InstallAware.Visible := True;..IF (Glass.Caption = TRUE) THEN Install.Visible := True;..IF (Glass.Caption = TRUE) THEN Separator.Visible := False;..IF (Glass.Caption = TRUE) THEN InstallAware.Visible := False;..IF (Glass.Caption <> TRUE) THEN Install.Visible := False;..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):161471
                Entropy (8bit):2.01262132228771
                Encrypted:false
                SSDEEP:
                MD5:1FC44F157739B702C26CFBD0397B4A6D
                SHA1:8EAFD74C123227D78D444FEF0F620B207B5EECD4
                SHA-256:9BDE398EF7EE5508A8533F71C9F3432C5BDC1CB3E59BE14B0C9CDE9F77D5A294
                SHA-512:C90E58DFFBFBEA44DB07637C7F8748A5C28EA071D49FC014AD378841248EF028EFC0DF7899E4CD4BF7AD0F502AC8A8B7D2E996C35E204352A407D5A0EBD1B9F3
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..v..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.:..Picture.Data..i...TBitmap~i..BM~i......6...(.......:...........He..................V-..a8..`9..b=..nD..yJ..zL...S..d@..gC..jE..jF..mH..rL..tK..sM..zQ..kG .mI .lI%.rN$.tO&.pN).{R#.{U .{S$.rP*.tP).sR..{W..}Y*.vU2.|Z2.yY6.}[5.zZ8.}^;..X...V...[...`...f...a...f...l...o...z...|...r...z...q...w...|...\#..X'..]$..Y)..[,.._/..^4..e'..h#..i%..l+..t...d2..b4..f6..e:..g=..h?..j<..l<..q<..~)..|1..}8..eD..kF..oJ..mA..sC..rD..uH..xM..xS..}V..zJ.................../...3...4...?...<...1...6...8.....................................
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):1935
                Entropy (8bit):5.032880507423945
                Encrypted:false
                SSDEEP:
                MD5:BF999DDE33E63DDEFC93DCC78FA2ED67
                SHA1:55B507BD0FBF3D2CC8801C8C383D434D9372E0C9
                SHA-256:95512DD81F4EAD716AFFB1FAAE2C443FF0C749882DB03985A8C0035ECEE37EF4
                SHA-512:3E1A128B27A001EB73BCDA90CA633F61B9BB86A08EEF6B714D451BD72A1BABA4BAFA9D162DE08F5F2744D38711F75FB1F37004C213EA0A92A84DC4725412BBAC
                Malicious:false
                Reputation:unknown
                Preview:IF (checkSuccess.Caption = COMPLETE) THEN textComplete.Visible := True;..IF (checkSuccess.Caption = REBOOT) THEN textReboot.Visible := True;..IF (checkSuccess.Caption = CANCEL) THEN textCancelled.Visible := True;..IF (checkSuccess.Caption = ERROR) THEN textError.Visible := True;..IF (checkSuccess.Caption = COMPLETE) THEN RunNow.Visible := True;..IF (checkRemove.Caption = TRUE) THEN textRemove.Visible := True;..IF (checkSuccess.Caption = REBOOT) THEN RebootNow.Visible := True;..IF (checkSuccess.Caption <> COMPLETE) THEN textComplete.Visible := False;..IF (checkSuccess.Caption <> REBOOT) THEN textReboot.Visible := False;..IF (checkSuccess.Caption <> CANCEL) THEN textCancelled.Visible := False;..IF (checkSuccess.Caption <> ERROR) THEN textError.Visible := False;..IF (checkSuccess.Caption <> COMPLETE) THEN RunNow.Visible := False;..IF (checkRemove.Caption <> TRUE) THEN textRemove.Visible := False;..IF (checkRemove.Caption = TRUE) THEN textComplete.Visible := Fal
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):32515
                Entropy (8bit):3.2392237095249325
                Encrypted:false
                SSDEEP:
                MD5:9A87495839CA4357F293308C86139F03
                SHA1:0529F4612D004BAA1FE8806F6EAD5E78B3E76E55
                SHA-256:C623B82A8BE3EAD16900164C09AFEE00215DC1749A6DE8D4F381CF983A3F5CEB
                SHA-512:75F64D527924764598066D157C406FD18A00FA59EAB8D418724EF7E87B8B718EF57595118284710A08B17D7C287723AAF5F06383F877ADF77EFF7F7573AD665E
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..~..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................).....!..!..$..&..(..*..-..<..1..4..7..;...Z...j...l...m...v...y...~...~..A..F..F..M..I..M..P..Q..T..[..]..X..m..d..w...}..r..a..n..m...Z..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):502
                Entropy (8bit):4.896842553280578
                Encrypted:false
                SSDEEP:
                MD5:D312F2FDC09193A04578D688A2CA292D
                SHA1:54BD3AA4CC72E68FC613A4227CADA7AD702D795E
                SHA-256:DB1C3A93A00A46C77F3E8D19C5DA4D42C54CE58C9EB71B586E512ABEE2D46967
                SHA-512:A71514B0F31010F7BF23954BCE707A277CA765BC14DDED7D7870615528A7751E4B26E72BB826781BC4F57C2A7C75FCFB92C4BA781AAD58372CF6CECE39832D19
                Malicious:false
                Reputation:unknown
                Preview:IF (LicenseCheck.Checked = True) THEN Next.Enabled := True;..IF (LicenseCheck.Checked = False) THEN Next.Enabled := False;..IF (Glass.Caption <> TRUE) THEN Separator.Visible := True;..IF (Glass.Caption <> TRUE) THEN InstallAware.Visible := True;..IF (Glass.Caption = TRUE) THEN Install.Visible := True;..IF (Glass.Caption = TRUE) THEN Separator.Visible := False;..IF (Glass.Caption = TRUE) THEN InstallAware.Visible := False;..IF (Glass.Caption <> TRUE) THEN Install.Visible := False;..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):1390160
                Entropy (8bit):6.681471919067502
                Encrypted:false
                SSDEEP:
                MD5:B2DD162022B17AB6D10D995B0F077FE3
                SHA1:C102C365978DAC8527E4544EA092C91A44418792
                SHA-256:41C89468AB1A9C5505B271A7869C72F38A51B38438DC46818D7E16100F7CA67F
                SHA-512:04CF43719FAEA7751F5D22860B4460770B10993476614AC86E0882B88AD91C6FA114177DA9EAC5839641F3AD49BBC119976E1E1E916D335BAB21EB0C4252DC2F
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...uT:b.................~.........................Q....................................................................O....P..@=...`...Z..............P(..........................................................d[..\............................text....i.......j.................. ..`.itext...............n.............. ..`.data....O.......P..................@....bss....(T...............................idata..@=...P...>..................@....didata.............................@....edata..O...........................@..@.rdata..............................@..@.reloc..............................@..B.rsrc....Z...`...Z..................@..@....................................@..@........................................................
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):160624
                Entropy (8bit):1.9662006432706152
                Encrypted:false
                SSDEEP:
                MD5:B3C9C9EE0C9C2DCB15CF24D5DF20F4F3
                SHA1:3B1660EB617CB2751D9CCC79B8C025BD5A7B153B
                SHA-256:23D6D6041B3025A8B1817B5FC455067B534AD91DCB19A1D09509A3AE55065CED
                SHA-512:93C5B855AF462D9772754CB46307F5890735F7476D8ECF0F9CF213BC3A32EB4E19E3C48842A68F9D1DD29EAF2A8A2EE4712E917AB05BC121C18BFA77E3250811
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.\s..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.:..Picture.Data..i...TBitmap~i..BM~i......6...(.......:...........He..................V-..a8..`9..b=..nD..yJ..zL...S..d@..gC..jE..jF..mH..rL..tK..sM..zQ..kG .mI .lI%.rN$.tO&.pN).{R#.{U .{S$.rP*.tP).sR..{W..}Y*.vU2.|Z2.yY6.}[5.zZ8.}^;..X...V...[...`...f...a...f...l...o...z...|...r...z...q...w...|...\#..X'..]$..Y)..[,.._/..^4..e'..h#..i%..l+..t...d2..b4..f6..e:..g=..h?..j<..l<..q<..~)..|1..}8..eD..kF..oJ..mA..sC..rD..uH..xM..xS..}V..zJ.................../...3...4...?...<...1...6...8.....................................
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):32639
                Entropy (8bit):3.2633511856005843
                Encrypted:false
                SSDEEP:
                MD5:3B989C7730DF816A13A88B722A25B021
                SHA1:882F64912D28ED7C1EE1D59333E934CC73E1C50A
                SHA-256:9E7054257B4D608BC16547468B0E6D4AA06B0A0CF467CF76CD7ED169979E0B2C
                SHA-512:36E42A53E3F4956DD87DCBF6E36B43E9210B8A5195684228CCF7C465ECB7105505EAFF01F705B8B4D48631E21C02B443AB871D84415A1597FC4B52B22D18689F
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.k...TPF0.TfrmDesign.frmDesign.Left....Top.{.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................).....!..!..$..&..(..*..-..<..1..4..7..;...Z...j...l...m...v...y...~...~..A..F..F..M..I..M..P..Q..T..[..]..X..m..d..w...}..r..a..n..m...Z...
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):744
                Entropy (8bit):4.963019277603885
                Encrypted:false
                SSDEEP:
                MD5:172D6845744A1EC7DC233E9335C5A47C
                SHA1:F0E3CB9C55F0F0961EF496D3EBF532943FB155E1
                SHA-256:7AEF8EF0D965D2AEDDDF2FBC2B99BA2A3E5E96517BCD38ADB1A3315456D16E6F
                SHA-512:639D0D336EA949B877E12A0DB026FC3D085F3DD2B25A7C5CDCC8850CCD998FCA4364BB18D167454AEDB763793E9D251E08A1A3A06A46117FF0B5B2AE22E06643
                Malicious:false
                Reputation:unknown
                Preview:IF (checkWINST.Caption <> TRUE) THEN WINST.Visible := True;..IF (checkJS.Caption <> TRUE) THEN JS.Visible := True;..IF (checkDotNET.Caption <> TRUE) THEN dotNET.Visible := True;..IF (checkWINST.Caption = TRUE) THEN WINST.Visible := False;..IF (checkDotNET.Caption = TRUE) THEN dotNET.Visible := False;..IF (checkJS.Caption = TRUE) THEN JS.Visible := False;..IF (Glass.Caption <> TRUE) THEN Separator.Visible := True;..IF (Glass.Caption <> TRUE) THEN InstallAware.Visible := True;..IF (Glass.Caption = TRUE) THEN Install.Visible := True;..IF (Glass.Caption = TRUE) THEN Separator.Visible := False;..IF (Glass.Caption = TRUE) THEN InstallAware.Visible := False;..IF (Glass.Caption <> TRUE) THEN Install.Visible := False;..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):43482
                Entropy (8bit):4.168440625869399
                Encrypted:false
                SSDEEP:
                MD5:5C0175D2688D0942C2616E689B52C5F9
                SHA1:200FE3D32B6A593538F61E3D1AA2A860BC40A2EA
                SHA-256:00FD246E8C2E5C79A0753C5BFD0D37A21C1CC0B272312C127E0775DB94669392
                SHA-512:02440C85404465F8FD590BF6AA5FA4FF315A34B39A9B958C73B294AC139B6C6D9BAAC0CD26A769E62480C547A71F98ECB70D6BBDCA4390F4347DBBC80E780AB8
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0....TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................).....!..!..$..&..(..*..-..<..1..4..7..;...Z...j...l...m...v...y...~...~..A..F..F..M..I..M..P..Q..T..[..]..X..m..d..w...}..r..a..n..m...Z..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):666
                Entropy (8bit):4.809149901341814
                Encrypted:false
                SSDEEP:
                MD5:03D007FB3FC47A2F8CA6EB2C13881052
                SHA1:3212C3FB7FAA97630F849AD7EBA205D90EAC7EE3
                SHA-256:692786FB6BF3363DFDD0CDA8013986F4F63FD9209DA6BD1299CC8CF06275DF89
                SHA-512:A2193DFBB22D9F8EFB3CFFD8F2E4021A3213667F13F218EF1AA9B1DD2BF3044AF1E71CFB19497762A386B6CFB841C4C642C739A52471556ED7C3877907D6EA9E
                Malicious:false
                Reputation:unknown
                Preview:IF (TestRemove.Caption <> TRUE) THEN CaptionInstall.Visible := True;..IF (TestRemove.Caption = TRUE) THEN CaptionUninstall.Visible := True;..IF (TestRemove.Caption <> TRUE) THEN CaptionUninstall.Visible := False;..IF (TestRemove.Caption = TRUE) THEN CaptionInstall.Visible := False;..IF (Glass.Caption <> TRUE) THEN Separator.Visible := True;..IF (Glass.Caption <> TRUE) THEN InstallAware.Visible := True;..IF (Glass.Caption = TRUE) THEN Install.Visible := True;..IF (Glass.Caption = TRUE) THEN Separator.Visible := False;..IF (Glass.Caption = TRUE) THEN InstallAware.Visible := False;..IF (Glass.Caption <> TRUE) THEN Install.Visible := False;..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):43116
                Entropy (8bit):4.127536230542945
                Encrypted:false
                SSDEEP:
                MD5:AF75C73B31B45D4797A326367B1A696A
                SHA1:B2795FAA612F4BFAEDF79EF0DDC6CC7E43FB5801
                SHA-256:F5BD968E1580C2B47D800867A237D4F90CD7465E38219836E7792094354CBBD2
                SHA-512:9073543CBF566EB031E6EF257A670BD59535B568F2D5C480A4D9DF9470586234226EB232F8A18D64322477502FB3AFB14B2422827647B69CFD8AFB2CFD75E490
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.X...TPF0.TfrmDesign.frmDesign.Left....Top.w.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................).....!..!..$..&..(..*..-..<..1..4..7..;...Z...j...l...m...v...y...~...~..A..F..F..M..I..M..P..Q..T..[..]..X..m..d..w...}..r..a..n..m...Z...
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):32365
                Entropy (8bit):3.210637703795355
                Encrypted:false
                SSDEEP:
                MD5:8DB37E945737A642476551E6EA537ED5
                SHA1:2579ECFFD229F167398337358778E032AAAE3E3D
                SHA-256:4221122F990055367BE3AF2CCD9A8A6A28E4E8A8889B74BD543C70E96FF63527
                SHA-512:461CD4C6F01A82AC1C6D97968AF1B3CCD6E5D5D8C76C5CDD92822869335C379E8DD07A562DF787232D173588D9DCBC1E3071A5E5BE873D02DE6744BEE599AA92
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.Y~..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................).....!..!..$..&..(..*..-..<..1..4..7..;...Z...j...l...m...v...y...~...~..A..F..F..M..I..M..P..Q..T..[..]..X..m..d..w...}..r..a..n..m...Z..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):32609
                Entropy (8bit):3.2576929890359447
                Encrypted:false
                SSDEEP:
                MD5:357DC1A87B637A95C2255C15ABDB9765
                SHA1:B41DBE26DB3C8F489E32096535E7DF8AF5F7859C
                SHA-256:005829185AC1A56337D40D515C7E8DA84B06A8E7B7487477DE521861248645D0
                SHA-512:ABBBD816EDDE10AF7612ACCF8858434BD9C17443B92CD7E3966F44B2F624822EE123EAD2DA7F1EF686D76D13FE7C4923F1E3460E0681CB9C239462638D14F677
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.M...TPF0.TfrmDesign.frmDesign.Left....Top.z.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TLabel.Label5.Left.(.Top.H.Width.8.Height...Caption..&User Name:.FocusControl..Name...TLabel.Label6.Left.(.Top.x.Width.A.Height...Caption..&Organization:.FocusControl..Company...TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a......................................................
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):576
                Entropy (8bit):4.8398488933566055
                Encrypted:false
                SSDEEP:
                MD5:FF697C2FFA89894EC61F9ADF6839926E
                SHA1:25CA863E1866D72D2AB76F76B15A7705F2C0CD12
                SHA-256:C8FDC1180440954E7773ABFA450D153194FA675B8B2764F0300C00A73C989BAC
                SHA-512:A67389FBA944DEA454F7D4559911F745ADE10A8B3B5ED57A6741546AA4EF77FC47017BC7711A586A19EDFA3825517D78BA46A841B0AB7291B6145EA9B0E63A76
                Malicious:false
                Reputation:unknown
                Preview:IF (Name.Text <> ) THEN Next.Enabled := True;..IF (Company.Text <> ) THEN Next.Enabled := True;..IF (Name.Text = ) THEN Next.Enabled := False;..IF (Company.Text = ) THEN Next.Enabled := False;..IF (Glass.Caption <> TRUE) THEN Separator.Visible := True;..IF (Glass.Caption <> TRUE) THEN InstallAware.Visible := True;..IF (Glass.Caption = TRUE) THEN Install.Visible := True;..IF (Glass.Caption = TRUE) THEN Separator.Visible := False;..IF (Glass.Caption = TRUE) THEN InstallAware.Visible := False;..IF (Glass.Caption <> TRUE) THEN Install.Visible := False;..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):33341
                Entropy (8bit):3.3842477874818355
                Encrypted:false
                SSDEEP:
                MD5:8616C794648FD69FAC8F0F88EDB22E4E
                SHA1:DDDFECF6EA3719E9CEF5C406FD4D525AF7D74A61
                SHA-256:7E5099588AC9EB46983021CFDFCDDDBEFEBFE4CBD8388A531EDAD35FC3DA842D
                SHA-512:B1288B55785B0CA40F331AE92460F213A1C8D77037D5ABA6BBBD74882024ABDC8985E10899F4476CFF64D83F424957B11FD0B759B537E2216DB4E146B1CD09ED
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.)...TPF0.TfrmDesign.frmDesign.Left....Top.v.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................).....!..!..$..&..(..*..-..<..1..4..7..;...Z...j...l...m...v...y...~...~..A..F..F..M..I..M..P..Q..T..[..]..X..m..d..w...}..r..a..n..m...Z...
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):1096
                Entropy (8bit):4.80637071596533
                Encrypted:false
                SSDEEP:
                MD5:E30F9BD0EB3C6A3372F67E0F8886E28C
                SHA1:B390AAEDCE02E0A1A031506EE73C313221367BBF
                SHA-256:905BBFEDE6E19926541295E4599A14169CDC21392388DAE0EE1974A5C827D608
                SHA-512:CBDCA01D6A8E060307DA35E6F5F5F52D691F0245E285548454B391543680817783CB443046263BEF5BC3B7A774C503771403FC5B76069F02ADD8A72972CE67F8
                Malicious:false
                Reputation:unknown
                Preview:IF (Name.Text <> ) THEN Next.Enabled := True;..IF (Company.Text <> ) THEN Next.Enabled := True;..IF (Serial1.Text <> ) THEN Next.Enabled := True;..IF (Serial2.Text <> ) THEN Next.Enabled := True;..IF (Serial3.Text <> ) THEN Next.Enabled := True;..IF (Serial4.Text <> ) THEN Next.Enabled := True;..IF (Serial5.Text <> ) THEN Next.Enabled := True;..IF (Name.Text = ) THEN Next.Enabled := False;..IF (Company.Text = ) THEN Next.Enabled := False;..IF (Serial1.Text = ) THEN Next.Enabled := False;..IF (Serial2.Text = ) THEN Next.Enabled := False;..IF (Serial3.Text = ) THEN Next.Enabled := False;..IF (Serial4.Text = ) THEN Next.Enabled := False;..IF (Serial5.Text = ) THEN Next.Enabled := False;..IF (Glass.Caption <> TRUE) THEN Separator.Visible := True;..IF (Glass.Caption <> TRUE) THEN InstallAware.Visible := True;..IF (Glass.Caption = TRUE) THEN Install.Visible := True;..IF (Glass.Caption = TRUE) THEN Separator.Visible := False;..IF (Glass.Caption = TRUE) THE
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):33637
                Entropy (8bit):3.431633511700928
                Encrypted:false
                SSDEEP:
                MD5:0ED309FE577738BE9F9EC6E6D4630658
                SHA1:3D22B4956C8DA2C4E91D99C590E165710915AEC3
                SHA-256:D65D017C4E6F112F1959F6BBC50FDFF35348596BE68183A5570257A199EAC1A6
                SHA-512:10E4E1D32E0A47196D18EAFA4FFF03C7F7D36F3AF37E1A0A3DCDE04ADEB3BBF2B3CE51A76D8236CE60AF63D813469BB20E28E997F10BB7986E39DF97B851BFC7
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.Q...TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TLabel.Label4.Left.(.Top.H.Width.I..Height.!.AutoSize..Caption..Please select a setup type..WordWrap....TBevel.Bevel2.Left...Top.:.Width....Height...Shape..bsTopLine...TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................)..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):160094
                Entropy (8bit):1.9356018985653418
                Encrypted:false
                SSDEEP:
                MD5:72FB03688EB1DC0BFB2EC47EFC219136
                SHA1:4C05F9B7F93B9CAEFDFBDE71AEFA33662E30284B
                SHA-256:CFEBA603367D7CE269E6806BEF49E135370CB4AE80EA575442DCE0833FDB991A
                SHA-512:6FA85A87C2BB0ADC4F699557D5C56A7D714E3852B1531E8AE3516195BB4FED29E6278966192F6A5068D166938760F42E44F355AF0735B3291D1DEC01357E52C1
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.Jq..TPF0.TfrmDesign.frmDesign.Left....Top.~.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.:..Picture.Data..i...TBitmap~i..BM~i......6...(.......:...........He..................V-..a8..`9..b=..nD..yJ..zL...S..d@..gC..jE..jF..mH..rL..tK..sM..zQ..kG .mI .lI%.rN$.tO&.pN).{R#.{U .{S$.rP*.tP).sR..{W..}Y*.vU2.|Z2.yY6.}[5.zZ8.}^;..X...V...[...`...f...a...f...l...o...z...|...r...z...q...w...|...\#..X'..]$..Y)..[,.._/..^4..e'..h#..i%..l+..t...d2..b4..f6..e:..g=..h?..j<..l<..q<..~)..|1..}8..eD..kF..oJ..mA..sC..rD..uH..xM..xS..}V..zJ.................../...3...4...?...<...1...6...8......................................
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):33346
                Entropy (8bit):3.385772495039534
                Encrypted:false
                SSDEEP:
                MD5:79A6D4AC0D44492941DBF1BCF729FCE0
                SHA1:B9A4351BA665D5F190FDCEAAC2F278214E402628
                SHA-256:ED50635652C5E71DD4EE1FBEB5B64E312235D3215C519E2DA2966FF44C61745B
                SHA-512:D0B8A675193F05FFB8A71624E67A0FB63BE6433C73798B675486F6D86181DDE52E1910E51A27E7A61932A0360E2236BE3493196497D9B7C198A8B8CE5F6C2808
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0.....TPF0.TfrmDesign.frmDesign.Left....Top.z.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................).....!..!..$..&..(..*..-..<..1..4..7..;...Z...j...l...m...v...y...~...~..A..F..F..M..I..M..P..Q..T..[..]..X..m..d..w...}..r..a..n..m...Z...
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):602
                Entropy (8bit):4.858794405298382
                Encrypted:false
                SSDEEP:
                MD5:5622CBE0342EA56DBEDDB3F036450AE9
                SHA1:97D52E9CE2FE1BA92BA141BCC66D2ECC6EC93978
                SHA-256:19878CE6F272ECDBE413786244A8476214F99445EBB85F307E92B07F2A4C8869
                SHA-512:C1E7CB7493635D368FBB7DA741353C82CB389488E1D8C32CB769FADACE21BC27416E59D2A9525A8DAC1D69195679CE91120496E7A74BF44377E91D97267B231F
                Malicious:false
                Reputation:unknown
                Preview:IF (MenuGroup.Text <> ) THEN Next.Enabled := True;..IF (MenuGroup.Text = ) THEN Next.Enabled := False;..IF (ISNT.Caption = TRUE) THEN AllUsers.Enabled := True;..IF (ISNT.Caption <> TRUE) THEN AllUsers.Enabled := False;..IF (Glass.Caption <> TRUE) THEN Separator.Visible := True;..IF (Glass.Caption <> TRUE) THEN InstallAware.Visible := True;..IF (Glass.Caption = TRUE) THEN Install.Visible := True;..IF (Glass.Caption = TRUE) THEN Separator.Visible := False;..IF (Glass.Caption = TRUE) THEN InstallAware.Visible := False;..IF (Glass.Caption <> TRUE) THEN Install.Visible := False;..
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):160013
                Entropy (8bit):1.9309569759113825
                Encrypted:false
                SSDEEP:
                MD5:90F5FF6EDDCCA361D3D359958A97D5A4
                SHA1:85AF264588C053310154318DAB63F754584206D9
                SHA-256:8A9CE30F887652B86334075B2E42E5B76F48075928CE56C53C4D23E375DD546F
                SHA-512:D8A03D9E20292330E3736F178D1B6315CE88B3C623A89C527C5EA33999FD4395A1D98DC95F7632CE0AAD4D9853EA98F36CD641E36E5AA118FECE247ED24E5D43
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..p..TPF0.TfrmDesign.frmDesign.Left....Top.~.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.:..Picture.Data..i...TBitmap~i..BM~i......6...(.......:...........He..................V-..a8..`9..b=..nD..yJ..zL...S..d@..gC..jE..jF..mH..rL..tK..sM..zQ..kG .mI .lI%.rN$.tO&.pN).{R#.{U .{S$.rP*.tP).sR..{W..}Y*.vU2.|Z2.yY6.}[5.zZ8.}^;..X...V...[...`...f...a...f...l...o...z...|...r...z...q...w...|...\#..X'..]$..Y)..[,.._/..^4..e'..h#..i%..l+..t...d2..b4..f6..e:..g=..h?..j<..l<..q<..~)..|1..}8..eD..kF..oJ..mA..sC..rD..uH..xM..xS..}V..zJ.................../...3...4...?...<...1...6...8......................................
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:JPEG XL codestream
                Category:dropped
                Size (bytes):32251
                Entropy (8bit):3.1896653509607855
                Encrypted:false
                SSDEEP:
                MD5:8AA68DEE4B3D18226980261469A560ED
                SHA1:E359A76C34D1F906690054A871C85DFA3A1C88A4
                SHA-256:D2267023E1F38FA5E44AFDF55B6DD485E25F2F1A8EC82C9E93EB8F137F0FBA2F
                SHA-512:6FC30F309A79C6A5661E6673B94258B0C1A240ED9934CB3D6A65C76CAAEDA032001A8F4C79416C76D9F278A0ADDFF595D04B1D60A0924363CEBB97311659CF6C
                Malicious:false
                Reputation:unknown
                Preview:...TFRMDESIGN.0..}..TPF0.TfrmDesign.frmDesign.Left....Top.z.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight.h..ClientWidth....Color..clBtnFace.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight...GlassFrame.Bottom./..TImage.Image1.Left...Top...Width....Height.;.Picture.Data.~w...TBitmaprw..BMrw......6...(.......;...........<s..................V-..^4..^6.._8..g;..a9..oB..xI..iB..gB..rK..nJ#.qN(.rP*.wT(.sQ,.uT/.wV2.}[1.zY6.~\5.|\9..P...W...^..._...e...c...i...l...s...{...y...z...|.......Z!.._2..i<..dB..jJ..mM..sF..zO..}O..sU..uW..uX..z^..}P..}a..........................................................).....!..!..$..&..(..*..-..<..1..4..7..;...Z...j...l...m...v...y...~...~..A..F..F..M..I..M..P..Q..T..[..]..X..m..d..w...}..r..a..n..m...Z...
                Process:C:\ProgramData\mia533A.tmp\resa launcher install.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):4884
                Entropy (8bit):5.389044027373165
                Encrypted:false
                SSDEEP:
                MD5:6FF9C3D5976FA662C63466D276769F12
                SHA1:8F3320A497A2DDE0C8F0A0C761C2F8E83F0B0D0A
                SHA-256:E7F3042311243941E8DB3899813963C359F8EA59D08280C5514D955552AA922D
                SHA-512:E5500547370E24396C5114AF676B4F052F2598A129C8DB0969F6F2DDA715DC0476CBB963E1B1E4AD83CE2C98DBC92A68C7978F2D084A96AFC24548D9AE76C837
                Malicious:false
                Reputation:unknown
                Preview:SourceDir..C:\PROGRA~3\{FF44E~1\..$ex..MEDIAPACKAGEPATH..\PROGRA~3\..$ex..A607A9F5C..FALSE..$ex..A8E136A7B..FALSE..$ex..A851024AE..FALSE..$ex..AF82E73DF..FALSE..$ex..A5D8AC0F0..FALSE..$ex..AF4142F16..FALSE..$ex..A607A9F5C..TRUE..$ex..P607A9F5C_1..C:\ResaApps..$ex..A8E136A7B..TRUE..$ex..P8E136A7B_1..C:\Users\user\Desktop\..$ex..P8E136A7B_2..C:\ResaApps\ResaLauncher.exe..$ex..P8E136A7B_3....$ex..P8E136A7B_4..C:\ResaApps..$ex..A851024AE..TRUE..$ex..P851024AE_1..C:\ResaApps\Business_Services..$ex..AF82E73DF..TRUE..$ex..PF82E73DF_1..C:\ResaApps\Reports..$ex..A5D8AC0F0..TRUE..$ex..P5D8AC0F0_1..C:\ResaApps\Business_Services\TaxControls..$ex..AF4142F16..TRUE..$ex..PF4142F16_1..C:\ResaApps\Business_Services\TaxControls..$ex..MSINTEMP..C:\Users\user\AppData\Local\Temp\..$ex..PREREQ..TRUE..$ex..QUICKLAUNCHDIR..C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\..$ex..WINSYSDIR..C:\Windows\SysWOW64\..$ex..WINDIR..C:\Windows\..$ex..ABORTEDONERROR..FALSE..$ex..DATESEPARATOR
                Process:C:\ProgramData\mia7875.tmp\crystal 8.5 for w11.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):15617
                Entropy (8bit):5.233545255905464
                Encrypted:false
                SSDEEP:
                MD5:407B98A343FDC36BB589A5A76FAF1143
                SHA1:54DB7E5D3CD37D648F99AB213B4CB496AA42D66C
                SHA-256:FBEAA1E8D4073859D9DDBDB2627C2BC2884666D3B16F876A83B7953E21A5E4D4
                SHA-512:86A8C3778A47A57BBCD97F72DDFD1774DF76791F5076F3D90516AE3D3D90686A4E956AAAF2C994BCCA1F3B996CECC8FA2B87787FEE15291D9E946A698F4E0851
                Malicious:false
                Reputation:unknown
                Preview:SourceDir..C:\PROGRA~3\mia7875.tmp\data\..$ex..MEDIAPACKAGEPATH..\PROGRA~3\mia7875.tmp\..$ex..A8B01F5B2..FALSE..$ex..A883718..FALSE..$ex..ACABD959B..FALSE..$ex..A26E8E8A..FALSE..$ex..A94B3D4EC..FALSE..$ex..AE32DAA77..FALSE..$ex..A726C68BE..FALSE..$ex..A2AFBF32D..FALSE..$ex..A5161E481..FALSE..$ex..AE6C13C9B..FALSE..$ex..AA601C89B..FALSE..$ex..A13DA35D8..FALSE..$ex..AD9EFCC70..FALSE..$ex..AD446D6EB..FALSE..$ex..A6DC047F3..FALSE..$ex..A8FDFB1D7..FALSE..$ex..A455F3481..FALSE..$ex..A3BB8A745..FALSE..$ex..AB7A0E9B3..FALSE..$ex..AF91D79CA..FALSE..$ex..A8E3B9392..FALSE..$ex..AFACCD2C0..FALSE..$ex..ACE415E54..FALSE..$ex..A1041948F..FALSE..$ex..AAC2FB922..FALSE..$ex..A14806AD8..FALSE..$ex..ADA3FBFCA..FALSE..$ex..AFCFCFB4F..FALSE..$ex..A8489469B..FALSE..$ex..AF638DC57..FALSE..$ex..AA3E37DC2..FALSE..$ex..A4172DCD0..FALSE..$ex..AC01F740C..FALSE..$ex..A30081FF8..FALSE..$ex..AEF13AA58..FALSE..$ex..A7AD5685D..FALSE..$ex..A3E127F46..FALSE..$ex..A412317AF..FALSE..$ex..AC4C6F595..FALSE..$ex..AD7C8AF63..F
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):34896
                Entropy (8bit):4.04300312703144
                Encrypted:false
                SSDEEP:
                MD5:990F780C01634D37EF81244D86962E94
                SHA1:68119C336DCA72053D09158047AAD005546B5036
                SHA-256:FD84AC60A8C1E3E9157A70FCA9CFDAE15EC6F51BAF92A4A446D3F11DABD6141E
                SHA-512:D847DA0FA896FD176E57A04F8039B7D884076A2B5258754D87D18936CFD8564C0613855C52020ABE2368044A6F73283C06F38D3DAA110D7F3335D21DD3126809
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........@..!...!...!..*=...!..V....!...>...!...!...!..V....!..n'...!..V....!..Rich.!..........................PE..L...J(M8...........!.........@............... ....a@.........................`......................................0"..U.... ..<....@...............`..P(...P....................................................... ..P............................text...v........................... ..`.rdata....... ....... ..............@..@.data...h....0.......0..............@....rsrc........@.......@..............@..@.reloc..&....P.......P..............@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):38992
                Entropy (8bit):4.709796332334463
                Encrypted:false
                SSDEEP:
                MD5:9F6567DCB974E8D4C9BF71F7ED0E259F
                SHA1:4D1739C2D2F1FAB49A3DFACB5F593C142E1ADD8E
                SHA-256:818B36E8C7BED7142B0CE01BF05D2B1DDF4C92E96B3096CDFE88ADA759103ADC
                SHA-512:4CDD276D9DDB6B23F5A9BD51E5B34C8203CC8EA42E94A2BAFA026651FA2CF1E81A278FA1910E506895E3BFD5BB7439BE3B863CAA31AFEC1B5E08FAAFD861B65C
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......1=..u\x.u\x.u\x..@t.w\x..@v.t\x.u\y.[\x..Ck.|\x..|s.w\x..|r.p\x.Z~.t\x..||.v\x.Richu\x.................PE..L...J(M8...........!..... ...@.......*.......0....f@.........................p......9................................4.......0..x....P...............p..P(...`.......................................................0...............................text...0........ .................. ..`.rdata.......0.......0..............@..@.data...d....@.......@..............@....rsrc........P.......P..............@..@.reloc..,....`.......`..............@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):211024
                Entropy (8bit):6.398585686364429
                Encrypted:false
                SSDEEP:
                MD5:85B73A82CD3FEF9DDBB2A70CE5666398
                SHA1:320222EDF528196AF875D37F7A0BAC514D6C9ADF
                SHA-256:888B72263EA17EC7D980F37B4C7A778CDD9983B6FBB2373D9D558EEDB81B01FB
                SHA-512:37E6B9BD478F6C87B2A47D82A4F325066EC15B257435C090C9D6ED7DFEDD0758888F906AA235C77C9BE2FA11DC338F72636DF75049ADCF67BB35A05AAEA04A72
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Z...;...;...;...$...;..'...;..v'...;..$...;..$...;..$...;.......;..$...;..$...;...;..k;.......;..2=...;.......;..Rich.;..................PE..L.....!?...........!.....@..........}........P......................................a.......................................x...........P...............P(.......#...................................................P...............................text....4.......@.................. ..`.rdata..G_...P...`...P..............@..@.data............ ..................@....rsrc...P...........................@..@.reloc..6........0..................@..B........................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):88144
                Entropy (8bit):5.59077495986769
                Encrypted:false
                SSDEEP:
                MD5:6839E2CD027F11B8FC1735A919CC946F
                SHA1:C9218E0828842DF6FC0FADAE5060727E91C67F4C
                SHA-256:F96CA9C352AC8C9D5BFDE00D9C9620891202EAA5AE20DFA2171721B3CADE4495
                SHA-512:7B25329391B2BF01913CE651CAF1228B136E8A26653CEFA9417385AD599997183BCBDD0C38D8D059B6FAFA7BC5CAFAF6008063A929C59A33BA398FF4F7EB4164
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Yb..............f...............@!......@!......@!.........._...........B!...............#......Rich............................PE..L...-x.;...........!................s........................................0..........................................Y...x...d........K...........0..P(... ..0....................................................................................text... ........................... ..`.rdata..............................@..@.data...............................@....rsrc....K.......P..................@..@.reloc....... ....... ..............@..B........................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):63568
                Entropy (8bit):5.126604411258866
                Encrypted:false
                SSDEEP:
                MD5:8232AD06857B16A44CB2CE2E297BF575
                SHA1:DCD566C13E12707871196B919FF79C4E0F349F9E
                SHA-256:089AC0333581C7151D74B577D82C32FA50AAC4926C5CCC3F33E088B6E8BB1B70
                SHA-512:6CB6002FE53827B22DAE3E1CCB9286EFCDAF83D84BF6FAFFD9FE51B32910C8261895AB37AECAC930BC13018420581849B9571487A09BBAC5D1ED0DB6155F4D28
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......q..5...5...5...N...6.......4......1...5...w...W..2...j...3.....4.....6...Rich5...........................PE..L...B..<...........!.....P...p.......\.......`......................................,................................f..(....a..d........3..............P(...........................................................`...............................text....M.......P.................. ..`.rdata.......`.......`..............@..@.data........p.......p..............@....rsrc....3.......@..................@..@.reloc..B...........................@..B........................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):67664
                Entropy (8bit):5.516058741583143
                Encrypted:false
                SSDEEP:
                MD5:BBE6C99647AAB519D40FC2C38376D4BD
                SHA1:71EF6CAFB3D3EE47CEE2CF36F649AF93812B0CF5
                SHA-256:67A732439F65786DB81933B48E000D56203A501046F81B3512F2164BB157E4DA
                SHA-512:57D960911D2B61AAAB682F061A57CE94475A93C3477F11A21B35308A9AFEACE74008EEA101BABF6DF82333895C7E0B845B9F869EBCC465155CCDAD91FE294582
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$................................................^.....................................u................."......Rich...................PE..L.....{:...........!.....`...........a.......p....g@....................................................................>...`...........H,..............P(......................................................|....p..x............................text....Y.......`.................. ..`.rdata.......p... ...p..............@..@.data...............................@....rsrc...H,.......0..................@..@.reloc..............................@..B.C88....3m9B...P .:M...P .:Z...Q .:e...Q .:o...........MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.ole32.dll.OLEAUT32.dll.............................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):108624
                Entropy (8bit):6.134256716261533
                Encrypted:false
                SSDEEP:
                MD5:1B8A08F7939DF348C327EAC8FC305711
                SHA1:DC1C933E7231769D113123C35A18B1F8C61C0BB7
                SHA-256:CC0AD7D23BC6DA5816E6993E4DD5B9DA75B86DE233F594383509F812B160DB0F
                SHA-512:41802B4149C4599D93218BABB887650630A48417904337A33E9468F33331287A73D6B1CFC82837D3B2AB2D8C2E674EFEDDE8624512E86CD365F2C0855A1D9C5E
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........`.[...[...[... ..._......Z.......Y......._.......Y...[...P...[...d...9...^.......Q.......Z.......Z...Rich[...................PE..L.....{:...........!..... ...P.......,.......0....t@.................................................................8.......3..d....P..................P(...p..\...............................................X....0..(............................text............ .................. ..`.rdata..Q....0.......0..............@..@.data...H....@.......@..............@....rsrc........P... ...P..............@..@.reloc..N....p.......p..............@..BP .:(...P .:5.......@....3m9K...........KERNEL32.dll.USER32.dll.OCIW32.dll.MSVCRT.dll...................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):182352
                Entropy (8bit):5.99044612253015
                Encrypted:false
                SSDEEP:
                MD5:77086F2CB682BC5282284F6D14A01C29
                SHA1:06378B6A984778394E7765519C7613400FE13216
                SHA-256:7A3BA10FCEDB6E513AC8D5623196C87BA702F312BAD61E8DD5B95A5A2407BDD6
                SHA-512:A5920FA929D4E2369AD4540ECDBF0C5668D91BBC0545E8FA29513F2D192CDE21FAA1CA50B11D505D57B7FEF5B24E477D8525B2FAE8D6DDC54FE1914855E00931
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......E.u.............z.......n...............n.......n...................j...c..............................Rich....................PE..L.....{>...........!................;...............................................9...................................&.......x....@...E..............P(...........................................................................................text............................... ..`.rdata........... ..................@..@.data........ ....... ..............@....rsrc....E...@...P...0..............@..@.reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):178256
                Entropy (8bit):6.014990238635874
                Encrypted:false
                SSDEEP:
                MD5:0D494DEE0BD8334125A978BA15D1FC78
                SHA1:CC0EB61D20E5FC9C91E94FBBE9284DB0D5CCEB67
                SHA-256:04B957C64E2F345CA3CF0B2D0C756F5FFBCF9EE1D681E903381A728AD0AEC890
                SHA-512:5605FAEEF29220EE0C2B706F47901C9AB9BC805990B566B35A5E06677111408356E9EBBCE6E7972AF489B850F2044376FC1DD552548A0DBB84E916F115DF2495
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....l...l...l...g...l.X<f.N.l.X<g...l...b...l...l...l.g.....l...m.s.l.Z<g.2.l...j...l..>h...l.Rich..l.................PE..L.....{:...........!...............................@........................................................................@...x....0...E..............P(...........................................................................................text............................... ..`.rdata...&.......0..................@..@.data....Y.......P..................@....rsrc....E...0...P... ..............@..@.reloc........... ...p..............@..BP .:8...P .:E...P .:O...P .:Z.....};g...P .:t...........KERNEL32.dll.NTDLL.DLL.USER32.dll.ADVAPI32.dll.COMCTL32.dll.GDI32.dll...................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):178256
                Entropy (8bit):5.999826354992213
                Encrypted:false
                SSDEEP:
                MD5:18AC26398E1123E82FB9F9C854F73B72
                SHA1:325A63589BB7202FFD3DF8341D1BB96DB207781B
                SHA-256:78A49BE5CA2DF4CC6DED61B7ACDD3359F8ED3CFE74128BB25F056DDC62171EF6
                SHA-512:AE0903CC9CF42A7698534A5C7AD02633AC4B224EABB51F2F57EFCE2490C053353934CDF2B99DA4522E341C3C98E306D2B28EDFF340F3A671829BB26B55DEE9FB
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........M...............D.....8.....D.....S.............................|.....D.....Rich...........PE..L....53<...........!................................................................*...........................................x.... ...L..............P(...p.......................................................................................text............................... ..`.rdata..=........ ..................@..@.data............ ..................@....rsrc....L... ...P... ..............@..@.reloc.......p... ...p..............@..B................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):186448
                Entropy (8bit):6.056007262330745
                Encrypted:false
                SSDEEP:
                MD5:91D1239E07894778F8603E0FF98ED6E5
                SHA1:828DC8DEBD4148724FC2503EF7BC1CFF50DE4DB3
                SHA-256:B1A48CB9D010DB495BBF685FDFAA34A48C732397617E25561944EE6159F90E66
                SHA-512:D817F5C452869DC99941275430303A5A148DA1A2340DE33BDD6E5D7E9150983096C5F846B843E3CAF63AF25CE282ED8C0C7006056DA2FD3C10CE6171C8325CF4
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........>RV._<.._<.._<..C0.._<..C2.._<..@6.._<..@7.._<..@8.._<.*C>.._<.._=.._<..@/.._<..|7.._<.jY:.._<.R.8.._<.Rich._<.................PE..L...$-V>...........!................................................................H...............................@...l............@...P..............P(..............................................................L............................text............................... ..`.rdata........... ..................@..@.data...."....... ..................@....rsrc....P...@...`...0..............@..@.reloc........... ..................@..B........................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):809040
                Entropy (8bit):5.582487435994583
                Encrypted:false
                SSDEEP:
                MD5:AD796DEA5473B3BF8318F42573B114AA
                SHA1:36B127FAC274D8993208EA71AC03A370B8E1D0ED
                SHA-256:61759664D4785F5EC4CBB625C2CDF8737DF7EE5FC1BEB1E84BA9A56F3916D5FF
                SHA-512:911155E0A0009383AB84C34FACDAE23B705FA53D3DE6FE1340755A17E097BB3FAE6D096095140D3476AF4CC682C526C00F9262657FAD24F14942CC567052AE35
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......=Y..y8..y8..y8...'..x8...'..}8...$..x8../'..]8..y8..e8..y8...9...'..j8..$...s8...$..b8..$....8......28..&...[8...>..x8......x8..Richy8..........................PE..L.....{:...........!.....p...........S.............@.........................p.......................................................................0..P(.......}...................................................................................text....j.......p.................. ..`.rdata..hL.......P..................@..@.data...............................@....idata..]7.......@...P..............@..@.rsrc...............................@..@.reloc..g...........................@..BP .:h...P .:u...P .:....P .:....U .:....R .:....P .:....R .:......};....k.M8....Q .:....Q .:............KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.WINSPOOL.DRV.ADVAPI32.dll.SHELL32.dll.COMCTL32.dll.oledlg.dll.o
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):165968
                Entropy (8bit):6.098694897169053
                Encrypted:false
                SSDEEP:
                MD5:8A8549E22C2672EEAF5BD3B79F63B217
                SHA1:F9450A83A5D44B0C7E08E0E148124B1292A21AFD
                SHA-256:15A105D5E3FD598B179BC550DB576C4D86A4E609D936E186565D928DC3E8F4CF
                SHA-512:EB7116100B789DFF35E265C0289F338F3F1D4C03EDBEAB7CC42557122461B3E38942CEF0203194CB2DFF7E504ABBA59B722EDBCD049DA39733A51CC645372A38
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......z...>.C>.C>.C..C;.Cc..C5.Cc..Cu.C..C(.C>.C=.C\.C7.C>.CM.Ca..C..C..C?.C...C?.CRich>.C................PE..L.....{:...........!...............................@................................................................P..........x.... ..x=...........`..P(...`.......................................................................................text....s.......................... ..`.rdata...#.......0..................@..@.data....V.......@..................@....rsrc...x=... ...@..................@..@.reloc.......`... ...@..............@..BP .:8...P .:E...P .:O.....};Z...P .:g...P .:q...........KERNEL32.dll.NTDLL.DLL.USER32.dll.COMCTL32.dll.GDI32.dll.ADVAPI32.dll...................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):178320
                Entropy (8bit):6.022489488812741
                Encrypted:false
                SSDEEP:
                MD5:6AFA55D12D8D6D52A6BAEFB04A8621DD
                SHA1:AA8660E6C5CAA11C4F1176ED2C62D47DE4857AD3
                SHA-256:72B4FEDBFC8DB565A4F1DAB84DDC45D2979A68F82D6F2709EE441D421B0D2510
                SHA-512:440F43090FF9FEDCE8A9FE0A35DBBF9EB34CBC434C7B128100FF147A4D32CEE9ED2F7E1AE15CD8D4FDBFBFDD1B26F2A7774188C197EAC141C8C612B418E5CEF9
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......q...5b..5b..5b..N~..1b...~..7b..Z}..7b..Z}..1b..Z}..7b..5b..Sb..W}..2b..5b...b..3A.. b...d..4b...B..4b..Rich5b..................PE..L.....e=...........!................)...............................................9...................................k...@...x.... ..`S..........@...P(.......... ................................................... ............................text............................... ..`.rdata........... ..................@..@.data...P...........................@....rsrc...`S... ...`..................@..@.reloc..(........ ...p..............@..B........................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):112720
                Entropy (8bit):5.759422769595531
                Encrypted:false
                SSDEEP:
                MD5:ED7634B6A644737505F0500FC02AF98D
                SHA1:FFA905C8713A46532354419E97B28FB80E3EFFE9
                SHA-256:C1F391E0B11EB5759B04C7CD2C979561662F2DA10D26D0C3712E5BA7975F11E4
                SHA-512:DE0C611B366487B96584C6E549F2081C391E819B888725A232A3A2A6CA905D8EAB59CCD1773CCB6DD0F2265066D141B1BBFF790EFD613C4FEDD850D6F1109B3E
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Xz.z...)...)...)...)...)...)...)A9.)u..)A9.)...)...)...)~..)...)...)...)...)...)C9.)...)...)...).;.)...)Rich...)........................PE..L...B.|:...........!.................~.............@................................y7..............................`.......x...d....`..................P(......................................................l....................................text...z........................... ..`.rdata..8........ ..................@..@.data....N.......@..................@....rsrc........`... ...P..............@..@.reloc........... ...p..............@..B..};0...P .:=...P .:J...P .:T...P .:_...........COMCTL32.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll........................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):63568
                Entropy (8bit):5.399420740449803
                Encrypted:false
                SSDEEP:
                MD5:B79B1E546E7BF730F0D78DEB62937132
                SHA1:D71809047C437734A379AC76BA0D6FCADC9B7D30
                SHA-256:3F02D4E61B38D11C238BBDEC155AFDA1D4012047829AAB0867D81CC0541CE504
                SHA-512:32E0D67BBDA75BCAD85E12410483E9770F115957839939864A9D652FE12A1F9785ACA47E441936AB18F174E21FD177A8902DFD435913FE74A99DB96080A6BE72
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........Q...?...?...?...3...?.M.1...?...5...?...;...?.I.=...?...>...?...,...?...4...?...9...?.1.;...?.Rich..?.........PE..L...l..?...........!.........@......................................................<...............................`.......h...d.......................P(......T.......................................................T............................text....q.......................... ..`.rdata..'...........................@..@.data...............................@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):75856
                Entropy (8bit):5.405184170143678
                Encrypted:false
                SSDEEP:
                MD5:AFBF9EB82B3504E78282D715D61C3E8A
                SHA1:B0747D9BD7691DA0F6751A321B7AACF05B2EC183
                SHA-256:C29B9D6F3ACEB652A983443C69F1A8713AFA76CCCE9329D983E5FA9D5D0971F3
                SHA-512:28FF0A7EB660638108022058FD5AFA926423918714D88ADEB3DC88285B21D079BE72BBF645380407352D3DFEC2C2002494B9DD3EEFCFD74487890E4B8AD17FC5
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........b.................6#................6#...........6#....Rich...................PE..L...J(M8...........!.........P....................p@...........................................................................P.......................P(......`.......................................................d............................text...P........................... ..`.rdata..............................@..@.data...|...........................@....rsrc............ ..................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):34896
                Entropy (8bit):4.239934467719819
                Encrypted:false
                SSDEEP:
                MD5:12D2EFAD867044D0A85BFA96EBFD3C29
                SHA1:FA4A9371F30855B9A051D8A39E41057D742C4FC7
                SHA-256:FAD2754354C76F608E31A49BF930BACF0FFF137164B24C1C1475B22495D9C123
                SHA-512:8EE9CC4DF2EA8D8BDBE4E94270557A7CFFD2A65089CD0A3ABC1D7A6636B7D1BD3B101113D6661B70CF94B82E7667458ABA225C8CEC797DD40FF3CC3C93F14324
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.................j................................Rich..........................PE..L...L(M8...........!.........@............... .....@.........................`......................................"..F.... ..P....@..0............`..P(...P....................................................... ..d............................text...T........................... ..`.rdata..&.... ....... ..............@..@.data........0.......0..............@....rsrc...0....@.......@..............@..@.reloc..~....P.......P..............@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):116816
                Entropy (8bit):5.5184254381862035
                Encrypted:false
                SSDEEP:
                MD5:60EBCA1AAD45C4FFFE168DB41D50056C
                SHA1:553FA6B29CDCF798841D2243A484D3045F815D96
                SHA-256:9E94C837F51B3845C5C04FD26106E59B569D664F16A06124058E148C8F0F6448
                SHA-512:7DF5B6C1C87E43EC80DA8B9F40A7C7C5909F7085007D883E009BCCF24766A7D487CB7A4E7DB43F113322C10809CFFA1077E713F94D8B80EC6303BD1E61989272
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............H...H...H`..H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H(..H...H...H$..H...H...H...HRich...H........PE..L...4.v=...........!................;................................................................................:..e....2.......P..@...............P(...`.......................................................................................text............................... ..`.rdata.............................@..@.data...T....@.......@..............@....rsrc...@....P.......P..............@..@.reloc..x:...`...@...`..............@..B........................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):421200
                Entropy (8bit):6.595802017835318
                Encrypted:false
                SSDEEP:
                MD5:E3C817F7FE44CC870ECDBCBC3EA36132
                SHA1:2ADA702A0C143A7AE39B7DE16A4B5CC994D2548B
                SHA-256:D769FAFA2B3232DE9FA7153212BA287F68E745257F1C00FAFB511E7A02DE7ADF
                SHA-512:4FCF3FCDD27C97A714E173AA221F53DF6C152636D77DEA49E256A9788F2D3F2C2D7315DD0B4D72ECEFC553082F9149B8580779ABB39891A88907F16EC9E13CBE
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e..d...d...d.......d.......d...d..Cd..K*...d.......d.......d.......d.......d.......d.......d.......d..Rich.d..........................PE..L...A._M.........."!.................<.............x.................................{....@.................................<...<.... ...............V..P....0..D;..p................................/..@...............p............................text...u........................... ..`.data...$:.......,..................@....rsrc........ ......................@..@.reloc...S...0...T..................@..B........................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):773968
                Entropy (8bit):6.901569696995594
                Encrypted:false
                SSDEEP:
                MD5:BF38660A9125935658CFA3E53FDC7D65
                SHA1:0B51FB415EC89848F339F8989D323BEA722BFD70
                SHA-256:60C06E0FA4449314DA3A0A87C1A9D9577DF99226F943637E06F61188E5862EFA
                SHA-512:25F521FFE25A950D0F1A4DE63B04CB62E2A3B0E72E7405799586913208BF8F8FA52AA34E96A9CC6EE47AFCD41870F3AA0CD8289C53461D1B6E792D19B750C9A1
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:.y.~...~...~...w...}...~.......eD.....eD..+...eD..J...eD......eD......eD......eD......Rich~...................PE..L..."._M.........."!.........................0.....x................................u.....@..........................H......d...(.......................P.......$L...!..8...........................hE..@............................................text...!........................... ..`.data....Z...0...N..................@....rsrc................f..............@..@.reloc..$L.......N...j..............@..B................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Revision Number: {FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}, Number of Pages: 200, Title: Resa Launcher Install, Subject: Resa LauncherInstall Installation, Keywords: Installer, MSI, Database, Author: Wayne RESA, Comments: All rights reserved, Name of Creating Application: InstallAware, Security: 0, Template: Intel;1033, Number of Words: 8
                Category:dropped
                Size (bytes):798720
                Entropy (8bit):6.223672482923808
                Encrypted:false
                SSDEEP:
                MD5:EDB786433CBFD0842907E88E8A976DEC
                SHA1:8EC6E42D038D7397FE0D58C23DDB914A14E800F0
                SHA-256:323E436B30AB8BE9B73F7F7DC60CDA93FE20C8CAA18EB7CD72E31C9B8A0806BA
                SHA-512:080BB07F16855B2DD30FFEA5851B6017852B7B753A4253DFA52A00B5BF3D307EC9DE383AA69565BC74E1BA39531C8331647EF06BCCBDE84C4CE615A29A1A5043
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):389632
                Entropy (8bit):6.443465180760872
                Encrypted:false
                SSDEEP:
                MD5:89B5903624F9CDED346676E88F918693
                SHA1:162201E4E31FB327E0B16531C81041DC574A04A4
                SHA-256:851BB0A420E47AF2F49518FAE86E4B9755BD5DAA6E9EB3B2F1FC4585B6F05163
                SHA-512:FD2587EF52E43EC131E4D06A34306E038B85B98E9EE2866FFD117E906B019FBA6972B794BEC2A9E0FEF357E199A0D13E64A89D4356EA8BF6CAFD6A289B1B48A7
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...>=xQ............................d........ ....@.....................................................................E............p...&.......................}...................................................................................text............................... ..`.itext..|........................... ..`.data....,... ......................@....bss.....P...P.......8...................idata...............8..............@....didata..............J..............@....edata..E............L..............@..@.reloc...}.......~...N..............@..B.rsrc....&...p...&..................@..@....................................@..@................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):51098
                Entropy (8bit):5.507590688197263
                Encrypted:false
                SSDEEP:
                MD5:7EA44AC529FE5DEF77B089740B0FAF7C
                SHA1:E9944C4AE138426DDB23BF6D4D2BD7C4C6C45576
                SHA-256:889BB078F293159E41824926F19B4796FEECA315BE5A945F9F81ADB84F009704
                SHA-512:2C3260EB7C9A23797EBE6DDF3030973394840A5A207720392E2128ECDE15C1E89746854DBD7DB0699A6C23E0BA34A8B5E8A0EAB91791D09D56CE43283A43922D
                Malicious:false
                Reputation:unknown
                Preview:...@IXOS.@.....@.c.X.@.....@.....@.....@.....@.....@......&.{D19A7273-0D14-44C3-95A2-2FBB862BA70E}..Crystal 8.5 for W11..crystal 8.5 for w11.msi.@.....@.....@.....@........\PROGRA~3\mia7875.tmp\&.{34298CBE-CEDC-4FE1-85C1-841B00345C2F}.....@.....@.....@.....@.......@.....@.....@.......@......Crystal 8.5 for W11......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{3ADD4FAA-1C8F-4DA8-BBBB-26CA4343830B}..C:\Windows\SysWOW64\crpe32.dll.@.......@.....@.....@......&.{FC238125-ED70-4322-B4B7-719B36409CE9} .C:\Windows\SysWOW64\exlate32.dll.@.......@.....@.....@......&.{2CFC096A-175E-45AD-99AC-D32E7946A853}..C:\ResaApps\CrystalFiles\.@.......@.....@.....@......&.{B4FAA560-15A4-4DE3-B326-1E5EEED915C4}$.C:\ResaApps\CrystalFiles\barcode.dll.@.......@.....@.....@......&.{426DB683-838A-4493-BCE9-796514F8751D}%.C:\ResaApps\CrystalFiles\crxf_pdf.dll.@.......@.....@.....
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                Category:dropped
                Size (bytes):101464
                Entropy (8bit):6.244560484391965
                Encrypted:false
                SSDEEP:
                MD5:5FF85536C392F340FC5F1BB164F59934
                SHA1:33492BBFCADFCE18DA7283E2E8FD15CD07FFEFDE
                SHA-256:00C16418C2CAA6DD12037E3E8E816C52E6378CF4CEBDE0A85800307F9C70F755
                SHA-512:76B0DFE029F815EC2697479B4617307E436D38BF90055F995E617EF77E370BDF6FEF04E18778E73800669A92476EFCA4C945CE6C2889076E6B7E0083F32E5651
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........J.Y.$.Y.$.Y.$.P..^.$.Y.%...$.6..D.$.6....$.6..P.$.P..X.$....X.$.....X.$....X.$.RichY.$.........PE..d.....5O.........." .....&...&......(~...............................................U....@.........................................p3.......+..P............p.......P..X<......(... ................................................................................text....%.......&.................. ..`.data....%...@.......*..............@....pdata.......p.......<..............@..@.rsrc................H..............@..@.reloc...............J..............@..B................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                Category:dropped
                Size (bytes):491096
                Entropy (8bit):6.137661162866824
                Encrypted:false
                SSDEEP:
                MD5:8F06D5BAA6BD0B19A62C04ACAD5D9802
                SHA1:B14B4FAD9CC2C931CCBB47140163E860D2B60DD1
                SHA-256:2BCE639FBD49A230207FD25A91C56DEC1B4352A0633EBFC597A9A60BEEBFC1CB
                SHA-512:49439D573F83D59399B5637C5F93F9AF7343F5CDEA1509E1FCD82305D57303FA571A3993173AD58A051B1DEF11F6A0FDE9891EE9456C3BC2C2E121B3FE4B2F16
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........V.^.7...7...7..]@j..7...OE..7...7..z7...A}..7...A|..7...AH..7..oA}..7..oA|..7...OU..7..]@n..7..]@k..7..]@a..7..]@l..7..Rich.7..........................PE..d.....5O.........." .....................................................................@.................................................<...x................e...B..X<......T.......................................................P............................text............................... ..`.data....\.......,..................@....pdata...e.......f..................@..@.rsrc...............................@..@.reloc...............6..............@..B................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                Category:dropped
                Size (bytes):428632
                Entropy (8bit):6.0828959705666446
                Encrypted:false
                SSDEEP:
                MD5:4039644B083836605F30A93EF79EABD9
                SHA1:F20BFE23EB877BAD4636D282D50BDEE114E1E99D
                SHA-256:9206001DA97B5A87725276EE0824D4FA4F4FEDBE3EE8F5E373DD7F95BDE73C90
                SHA-512:B365E3E07D6CA8C3CE634CE4E0584A5A22448E33D78AD85EE90294E958796F4970D5E28E60751E2367887B1E8DAB7785428DBEE76BE5B04578888EA4B64BF462
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........k[..8[..8[..8...8N..8R.,8J..8[..8...84..8j..84..8...84.!8Q..8...8W..8...8\..8R.<8Z..8...8Z..8..~8\..8...8Z..8...8Z..8Rich[..8................PE..d.....5O.........." ................TX.........S....................................P.....@.........................................0.......$...........l.... ...^...N..X<...........................................................................................text.............................. ..`.data...pN.......$..................@....pdata...^... ...`..................@..@.rsrc...l............<..............@..@.reloc...............B..............@..B........................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):147260
                Entropy (8bit):6.550437132144939
                Encrypted:false
                SSDEEP:
                MD5:A161DC485AEAE86241F158A6F212017B
                SHA1:74029866FFEA391AF8C5B2A48825C5BD8A7CD5CC
                SHA-256:1901DB1F6C55F429A0161CB5E69495EBC6303CB70A1C77A9A1CAAB413C5B93E6
                SHA-512:BFD85C4A8E9F161BB8A5D76FB74A903F75A816CB3A52CC7C3D47A8C110D2D7B2BB2C0737A16134A5ABDFA23F5DD8438C4DB093652B81EB8465346F61BD11B0BD
                Malicious:false
                Reputation:unknown
                Preview:...@IXOS.@.....@.c.X.@.....@.....@.....@.....@.....@......&.{49D665A2-4C2A-476E-9AB8-FCC425F526FC}(.Microsoft SQL Server 2012 Native Client ..sqlncli.msi.@.....@4....@.....@......ARPIco..&.{B29CB6A0-B02A-4017-B7BF-746FA8C1356E}.....@.....@.....@.....@.......@.....@.....@.......@....(.Microsoft SQL Server 2012 Native Client ......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration...@"....@.....@.]....&.{6CC775C1-D2E1-48E0-9E02-37D5B0E9AE32}!.C:\Windows\SysWOW64\sqlncli11.dll.@.......@.....@.....@......&.{005126C0-E9E4-4547-B3EB-BBB747D3031A}..00:\SQLNCLI11.Enumerator\.@.......@.....@.....@......&.{932492BF-66A5-457A-988E-D16E8F282681}!.C:\Windows\system32\sqlncli11.dll.@.......@.....@.....@......&.{95E62AEB-A564-422B-8C9E-1C9CE33F662A}1.02:\SOFTWARE\Microsoft\SQLNCLI11\InstalledVersion.@.......@.....@.....@......&.{D0612BB3-AAC5-42B7-9DB4-FE2156769B39}R.02:\SOFTWARE\Microsoft\Micros
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):51800
                Entropy (8bit):6.674750394737739
                Encrypted:false
                SSDEEP:
                MD5:FA433515594A2E6FBEE5106DA583EE22
                SHA1:DB400631B8F4990060837BF7FEDE9C8B386BF257
                SHA-256:DBE7150D73B1187B7B1463133869D0478598D4E00DD19F06A3471F4186829286
                SHA-512:C1BE5BBA3339AF5C1067002B99366F8A25F85849FFBBF21CAC1F177A345F2AACE1CCF5FA0D5B81AABEFFA146884D35E6ADA76D0EE29DE38CFD61002718251E82
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\;g..Z...Z...Z...-...Z..."...Z...,...Z..w,...Z...Z...Z..w,...Z..w,...Z..w,...Z...-...Z...-..Z...-...Z...-...Z..Rich.Z..........................PE..L.....5O...........!.....t..........5?............%R.................................D....@.............................X....v..d.......p...............X<..............................................@............................................text....r.......t.................. ..`.data................x..............@....rsrc...p...........................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                Category:dropped
                Size (bytes):64088
                Entropy (8bit):6.33627104083093
                Encrypted:false
                SSDEEP:
                MD5:6D3940505D9764A918FA37BF1B9CF29C
                SHA1:5F81D446ADF0EC4F9D87DBBD2A1AEB1EE845E50C
                SHA-256:7DB93F9E42285A52DB3801FD5E72E4CBBE17B1577B25B1BA3DD400F3C492451E
                SHA-512:C9871B010F1AA24A5AD294F49C9FE0D99A1EE01B7C6FCBF2E501AE0E1787F6BF498E9D09D3804FC352704BF2359B5D737877CA11BE8ADADC1703EBA154B9A18E
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......b.%.&.K.&.K.&.K.....%.K./....K....$.K.I..%.K.&.J...K.I..'.K.I../.K.I...$.K./..'.K....'.K....%.K.....'.K....'.K.Rich&.K.........................PE..d.....5O.........." .................G........%R..........................................@............................................X...$...d.......p...............X<..............................................................h............................text...8........................... ..`.data...............................@....pdata..............................@..@.rsrc...p...........................@..@.reloc..\...........................@..B................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):144384
                Entropy (8bit):6.043448081977129
                Encrypted:false
                SSDEEP:
                MD5:6484BEE1546FEB56595EAACF5D019C55
                SHA1:CBFE2EBE0485E447F1887F52D5A3CFA480A8FBBE
                SHA-256:FB73F1E2A71635F6F1F10FB7C7B738E4CE5125C3841B1A656A5F2CD406BDDFB2
                SHA-512:538A1B8981BAF6F35FE58CC862FAA5AF27D68E93572C5E4EF6719E1CF4A9B1A4AC9E61FFA22EBC1E9AEC0FDEB88AF54FE8834B8C384B596A889C07E63C031ECE
                Malicious:false
                Reputation:unknown
                Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...?=xQ.....................f......|.............@.....................................................................D....`..................................d+..................................................Xb.......p.......................text............................... ..`.itext.............................. ..`.data...h...........................@....bss.....N...............................idata.......`......................@....didata......p......................@....edata..D...........................@..@.reloc..d+.......,..................@..B.rsrc................"..............@..@.....................4..............@..@................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):3939
                Entropy (8bit):5.667653629706639
                Encrypted:false
                SSDEEP:
                MD5:C009E55EB4CD2555F337FCED833623B6
                SHA1:6782894782C209317668500B77AA2F29DAAC8FA0
                SHA-256:4F0FD370B7BE151CF50170EB124CB0009A82619781E99540B09EBA39D0DFDA9E
                SHA-512:312CC20055CAA61A81C3CCA57AEF88A73B2A9F612BE3386B0643A3BEF5A74CAD77326579BFC3900EED871DA24B6A50C85F05A424C458C2E7CB338A47C5241826
                Malicious:false
                Reputation:unknown
                Preview:...@IXOS.@.....@.c.X.@.....@.....@.....@.....@.....@......&.{7F9E06BB-5B40-4E0F-91B1-6A37A71A3390}..Resa Launcher Install..resa launcher install.msi.@.....@.....@.....@........\PROGRA~3\&.{FF44E8D3-41BA-4ACE-9A65-4CDAFDBA82FC}.....@.....@.....@.....@.......@.....@.....@.......@......Resa Launcher Install......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{3B5C697E-2C37-4E32-A295-4682808D1B8C}..C:\ResaApps\ResaLauncher.exe.@.......@.....@.....@......&.{92253176-E0AD-4F8B-822B-694BA86F85EC}..C:\Users\user\Desktop\.@.......@.....@.....@......&.{BAE2307C-296B-4267-825C-1BF18A246DD3}3.C:\ResaApps\Business_Services\ResaScannerHelper.exe.@.......@.....@.....@......&.{F3A84B07-45BD-4688-B32F-ED5295176E62}&.C:\ResaApps\Reports\ResaReportView.exe.@.......@.....@.....@......&.{9C5BE1D7-1412-4116-BA91-BD7C0F8A577F}9.C:\ResaApps\Business_Services\TaxControls\TaxC
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):20480
                Entropy (8bit):1.1623358406254187
                Encrypted:false
                SSDEEP:
                MD5:6BA8BE9933D819A90B9E82957B8AEDE3
                SHA1:2CE78A5FEBD7CC1CA7B518E31BF1E004593E8CB9
                SHA-256:F54467D23106DB0F7ABFEC310D788948FB5B211BE2437DA135B158D2B62EDA76
                SHA-512:5C2C1E81DACAAACA334A78536E7CDC4B8C26BF8445943FC04FF612D31CA17277B876D3525B884A5F330856655152D9541292BA5B4417F31D7B984BECFB7A8473
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):20480
                Entropy (8bit):1.2845940708912025
                Encrypted:false
                SSDEEP:
                MD5:750FD9DE71DA6721A5D1AF16FA77FC0B
                SHA1:7E5C1721766A041DAAF8C057B3A560EFA9FDF36C
                SHA-256:732934D1B65C610D64999E56CD641425F1B4F40B343241750DA8CE034321DFC7
                SHA-512:5609473F53C2BA676569E9B12EE470C50C021EE93AB084659A3D30FD91A814C755F820AE8B9A6678C7B87B98D05B40491E1D0D5E42721A87D9AFBA6CFDEDB040
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):28672
                Entropy (8bit):2.673181964145436
                Encrypted:false
                SSDEEP:
                MD5:A56B121A135082DBD0CB5A6CDC2B73AE
                SHA1:69C5D8B4B7932751F8C11B6481C7B6D939671188
                SHA-256:FE746C1EECA29332F009E71A8C74DA4B1F4A84D805341C1B1DCD8CA341D30DC4
                SHA-512:42F3B57B65CB50A07AD53B1192A1575F0C10919568D21820FC4F584FE43F8F2614A8E6527FB59DAC5656108B601BD8796A8C735566EE17DF5020F7D1348065DE
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):20480
                Entropy (8bit):1.4947037784999815
                Encrypted:false
                SSDEEP:
                MD5:7E346560F6223E0B9849F09839D293A0
                SHA1:E028E5F699EBE35469C7AB7144C516E477D6FA0F
                SHA-256:692774DBBDA2F23079C6FD158F54C8133AF88E5C79B520017E13DA1EE5FA89A3
                SHA-512:9833F54B03E6CF2581B90C92A833A595CC048AE426009BAC1119627ECC2AF03F16E524A0FED27E4FDA8374A293D1D6D85548C930DB116754ED5C1AB0083B37F1
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
                Category:dropped
                Size (bytes):5430
                Entropy (8bit):3.9632614846212664
                Encrypted:false
                SSDEEP:
                MD5:891EACB881537F9EE9FFB964F5D78DFA
                SHA1:25799A1281EA9624884289CF88536E4456CB07EC
                SHA-256:A5B7E6BB0C75CA1953929B03C6AFAD959FE137DA3730D6A93AA9CEE48F53229B
                SHA-512:E7F1FAF4BEBB71170BB83D21B6F5D4E5F087C6898FCE2B6240E10FC3B6D20C0E6791E7D47545FF4FFF291F9AAD2D2DF5E33C0159528DAE1ABC18EB3EBBDFD1CE
                Malicious:false
                Reputation:unknown
                Preview:...... .... .....&......... .h.......(... ...@..... ..........................................................................................................................................................................................tf..se..rc..pb..oa..n_..m^..l]..l\.~j[.~iZ.}iY.|gX.{gW.{fV.zfV.zeU..............................................................wi...............................................{fW..............................................................yk............................................................|hX..............................................................{n.................................................9..........}iY..............................................................~q.............................................'...1...........k\...............................................................t.............................................................m^.......................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                Category:dropped
                Size (bytes):403156
                Entropy (8bit):5.3596445483848925
                Encrypted:false
                SSDEEP:
                MD5:37594938DF32B4ED90CEC06D12819862
                SHA1:A1B3E42FE3E705E8401BE0B2F1F333AB699AAAE8
                SHA-256:39B536D99451A2E58721E693CB5A1C129687A308CECFA5DE666BD235357210A5
                SHA-512:122797CCCE7411FC7EC688344D8B121C65047FCE0D35605FD9F59777160D438E848814533A99D564B2D803CB038F5566DE3227CF8483938DB36070C49C436ACD
                Malicious:false
                Reputation:unknown
                Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                Process:C:\Program Files\Windows Defender\MpCmdRun.exe
                File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                Category:modified
                Size (bytes):2464
                Entropy (8bit):3.246703230844766
                Encrypted:false
                SSDEEP:
                MD5:4B36006AE20DB6ADBFEDBA36D035E048
                SHA1:8B4582C81960115BF10752222F43CB6B5AF61190
                SHA-256:AD46C261AC1F56387496C5EC681329959A4AC18696CC78C84CBCD0D38CA4580E
                SHA-512:8815A4FB808A929595F3A3F41D4C1C3F0293C2C9465401F9D263E64F4C50B0CA0940EDB584284C4297C960C18B5B8E6C29DBF3A8587245DB2594AD23BE3D6D65
                Malicious:false
                Reputation:unknown
                Preview:..........-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....M.p.C.m.d.R.u.n.:. .C.o.m.m.a.n.d. .L.i.n.e.:. .".C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.m.p.c.m.d.r.u.n...e.x.e.". .-.w.d.e.n.a.b.l.e..... .S.t.a.r.t. .T.i.m.e.:. .. W.e.d. .. M.a.y. .. 2.9. .. 2.0.2.4. .1.2.:.3.1.:.2.4.........M.p.E.n.s.u.r.e.P.r.o.c.e.s.s.M.i.t.i.g.a.t.i.o.n.P.o.l.i.c.y.:. .h.r. .=. .0.x.1.....W.D.E.n.a.b.l.e.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .W.S.C. .S.t.a.t.e. .I.n.f.o. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .A.n.t.i.V.i.r.u.s.P.r.o.d.u.c.t. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....d.i.s.p.l.a.y.N.a.m.e. .=. .[.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.].....p.a.t.h.T.o.S.i.g.n.e.d.P.r.o.d.u.c.t.E.x.e. .=. .[.w.i.n.d.o.w.s.d.
                Process:C:\Windows\System32\msiexec.exe
                File Type:MS Windows HtmlHelp Data
                Category:dropped
                Size (bytes):96009
                Entropy (8bit):7.666459604320129
                Encrypted:false
                SSDEEP:
                MD5:9FFC2D22C4AABAEBF536EC4DDD9EC626
                SHA1:ED12497D3B32A95424013334D4846048FC285947
                SHA-256:4B2BFECD90F83A05DB15C7146D2717353FA4CCEB4985FE10E402B1ED28556FDB
                SHA-512:2EABBFB29B5A7C4DA430683C1B45408A5E80F61AD89407C7172C9B78CF76F3B85A551209F576E67FFD656D817D019C78070B0D1B96B38A5643DB527AC7F6544B
                Malicious:false
                Reputation:unknown
                Preview:ITSF....`........T.........|.{.......".....|.{......."..`...............x.......T0.......0...............w..............ITSP....T...........................................j..].!......."..T...............PMGLJ................/..../#IDXHDR...s.../#ITBITS..../#IVB...[D./#STRINGS...+.x./#SYSTEM..v.W./#TOPICS...s.P./#URLSTR...?.l./#URLTBL...C.|./#WINDOWS...C.../$FIftiMain...f..../$OBJINST...'.?./$WWAssociativeLinks/..../$WWAssociativeLinks/Property...#../$WWKeywordLinks/..../$WWKeywordLinks/Property....../html/..../html/3761a704-4bf2-4ccc-9802-1de3af427519.htm...l.../html/4cb84b66-5a46-4000-951d-7ba8148dd273.htm...|.I./html/6854121d-429d-4d1b-9d64-342583e08378.htm...E.P./html/71e52c9e-df74-46dc-b9d8-20722461beb3.htm.....W./html/8a9c74cb-35b8-4807-a1ce-1ae74aecde8f.htm...l.u./html/a0f38beb-f3c4-40d1-9fb0-02c736bb1881.htm...a.../html/bb992526-6016-4782-ba41-e0e669780a36.htm...}.|./html/e45b8d4c-45b4-4dcd-a1a3-d00244464102.htm...y. ./html/feac158a-4dd8-4baa-8e72-4fabf3f16784.htm.....}./icons/
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):240216
                Entropy (8bit):4.387826686231161
                Encrypted:false
                SSDEEP:
                MD5:16CFA1D36714474C449E6CD7C5948E25
                SHA1:7BFCD9315D8CAEB927EB21A741DAD41DBBE43488
                SHA-256:E4801A0D27AFD5FC3FBFA5C30B92D74BC613461B6D719133D912CEC28EE943D1
                SHA-512:21FF5867920DF3A97C6269EE9B7AE2FB0E89B05BA90A17911D6EEEF83A22AE980A97DA5CDCB0FEE7C8182480D7A798B5275D7F19F10FBA5C820611979B74D3C3
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Uu]...3...3...3..c....3..c....3.Rich..3.........PE..L.....5O...........!.........l....................g9................................B.....@..............................................k...........n..X<...........................................................................................rsrc....k.......l..................@..@................................................................."..`.......................................p.......8.......P.......h............................................................u......................................................mx......nx..(....y..@....y..X....y..p....y.......y.......y.......y.......y....................I.....................0.......H.......`.......x........................... .......!.......".......#... ...$...8...F...P...G...h...J.......P...................................................(...
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):3005528
                Entropy (8bit):6.5887941207120635
                Encrypted:false
                SSDEEP:
                MD5:AE8801FB334DA187E5417E90F03D5A3C
                SHA1:35F899A28BE6DF60C166FE9139331A183D400858
                SHA-256:4F73610EDAA985E271CBF6C852A02FEE9C9B0A3C5D6922AC3650C3406CB115AD
                SHA-512:EF9F28C0618540BFF6AC708AE0486A89CA44B83CA98F60FA71A33353DA36C6777CE37FACBDAC48ADDE650F1EB40B3FB5305579E3DFFB383E2794781420C3135A
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......F..J..|...|...|.......|.......|.......|.....".|.m.....|...}.s.|.......|.m.....|.m.....|.m.....|.......|.......|.......|.......|.Rich..|.........................PE..L...uc6O...........!......)..................0*...88..........................-.......-...@..........(...............Z........)......P+...............-.X<...p+.\s..P.).8...............................@...............4............................text.....).......)................. ..`.data...L.....*.......).............@....sdbid...@....+..B....*.............@....rsrc........P+.......+.............@..@.reloc..\s...p+..t...,+.............@..B........................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                Category:dropped
                Size (bytes):240216
                Entropy (8bit):4.388240974155367
                Encrypted:false
                SSDEEP:
                MD5:BCADE83E1C8601B2A037124D4DD69B4B
                SHA1:AD5B4DF8D84AD45CD4BCC9C88ECE43A4C9813087
                SHA-256:E8839FBF712DA1007D505B8212AA07FED5E848A811C7AE2076BFFEB7DAE09D3A
                SHA-512:04992E322D4D867CA29FADE3F23FF1C07BD2C14E3602462EE186147207E344104862D7966003A1C68C955A439AACAC129E7E83D76D3D93F9589826B8E9FFC41C
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Uu]...3...3...3..c....3..c....3.Rich..3.........PE..d...=.5O.........." .........l................g9..........................................@..............................................................k...........n..X<...........................................................................................rsrc....k.......l..................@..@................................................."..`.......................................p.......8.......P.......h............................................................u......................................................mx......nx..(....y..@....y..X....y..p....y.......y.......y.......y.......y....................I.....................0.......H.......`.......x........................... .......!.......".......#... ...$...8...F...P...G...h...J.......P...................................................(...
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                Category:dropped
                Size (bytes):829264
                Entropy (8bit):6.55381739669424
                Encrypted:false
                SSDEEP:
                MD5:DF3CA8D16BDED6A54977B30E66864D33
                SHA1:B7B9349B33230C5B80886F5C1F0A42848661C883
                SHA-256:1D1A1AE540BA132F998D60D3622F0297B6E86AE399332C3B47462D7C0F560A36
                SHA-512:951B2F67C2F2EF1CFCD4B43BD3EE0E486CDBA7D04B4EA7259DF0E4B3112E360AEFB8DCD058BECCCACD99ACA7F56D4F9BD211075BD16B28C2661D562E50B423F0
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........pm...>...>...>..>...>...>F..>...>...>...>..>...>..>...>D..>...>...>...>...>...>...>Rich...>........................PE..d...J._M.........." ..........................sy............................. ............@.........................................pt.......`..(...............pb......P............................................................................................text...F........................... ..`.rdata..............................@..@.data...L}... ...R..................@....pdata..pb.......d...Z..............@..@_CONST..............................@...text.....2... ...4..................@.. data.........`......................@..@.rsrc................v..............@..@.reloc...............z..............@..B................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                Category:dropped
                Size (bytes):3481176
                Entropy (8bit):6.362538595143407
                Encrypted:false
                SSDEEP:
                MD5:5D0E785D061E7D7BD750ABA84782BC88
                SHA1:51761780CBCABB63D0AA92D0CCE269590022C022
                SHA-256:8FFFD0905009469CE19FC35907F74F1FED069DC206ABCA41F215EE1A2F76DC53
                SHA-512:603C35B37C19A0D4139F5CBE23847D5886127012C33C56058F2D156CB6920E1D0FE1F0FF68E576B6BD183CC736FA5CAB27299F08BA779743BBB81CA2079357D3
                Malicious:false
                Reputation:unknown
                Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........Q.4.0.g.0.g.0.g.Gig.0.g.HSg.0.g.H\g.0.g.HGg.0.g.FHg.0.g.0.g.2.g}~Lg.0.g.FJg.0.g.F~g.0.g.F.g.0.g.HWg.0.g.Glg.0.g.G.g[0.g.Gcg.0.g.Gng.0.gRich.0.g................PE..d....Q6O.........." .....,1.........<.........88.............................05......*5...@..................(...............................Y........4.......2.hT....4.X<....4.(U......8...............................................X............................text... *1......,1................. ..`.data....u...@1..j...01.............@....pdata..hT....2..V....2.............@..@.sdbid....... 4.......3.............@....rsrc.........4......r4.............@..@.reloc..(U....4..V....4.............@..B................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):32768
                Entropy (8bit):1.262068530799965
                Encrypted:false
                SSDEEP:
                MD5:B9E1AA1DE9C22DEDE7F6516797488063
                SHA1:442A6EF7E4A461D4BA914B1624138BFE669F2716
                SHA-256:FB00073CE8CBE2DB65D31C5FBEA5B48D30FD7D4CBD020640161B6202D0BF627E
                SHA-512:56AA2C0ED8FE9C45B59FABD4852E2950DFBB2C6BE516255E19AB02BAE1D0C5E6D3C7DE98699BD41B1E8E54FE50853E95383ABEF556B7048C7FB072830F5937A7
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):32768
                Entropy (8bit):0.1579120244334219
                Encrypted:false
                SSDEEP:
                MD5:9A756BEDE0495760B4403164C6404BB9
                SHA1:AB70DFFD792DD65A9040F00241FB8149AE629868
                SHA-256:39D48B2C23EA2C6285AD1EC035743B0A4C05A5983338118E01311CE84BCD7974
                SHA-512:DA89DB6B96EA499CF6ABA05F445FB0A757DA1E3297839C12D27AA370A5E10645D67ED339EC6AECA7B83788B80A815F19892547C334C327C8ADC76E6F2551EABB
                Malicious:false
                Reputation:unknown
                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):73728
                Entropy (8bit):0.6247676526015287
                Encrypted:false
                SSDEEP:
                MD5:0750DF8810D7FDE224A0E8092EE7751E
                SHA1:B7483709989A4FCE50EF0299297BFFDD0718BF18
                SHA-256:35613C2D81F0459777ECCBD0ED7C5485D6E21731B7B219B6B2894D06F0CE7B08
                SHA-512:BFC558FCEC1278D520EBEC01AD9CE125773274202C51AA82D8B1A5F7A44CD4A7EE4B10D3B30BE676CC0FDE615EA3F8294853AA23F6E1620C0D3BBC8E849C2D48
                Malicious:false
                Reputation:unknown
                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):73728
                Entropy (8bit):0.14069352956664521
                Encrypted:false
                SSDEEP:
                MD5:26E80E11697E2934A7EFE4488BC5D15E
                SHA1:B846D1748871ECE9D7BE6431D50706DA31E6DBA8
                SHA-256:8DCF48ED383D1CA2A9647A96AF5A644B94B4E784903EE60AAFB8C35C5B117097
                SHA-512:29C761622B792EB99956D4824328EDD0E3C16C3B0D488222CBA2AA745546BFC716215EE616A8344D6327D920A68997D01067E9220D124E1245019A81AF12E9B5
                Malicious:false
                Reputation:unknown
                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):20480
                Entropy (8bit):1.8437644349800695
                Encrypted:false
                SSDEEP:
                MD5:B5866B712F8915A076562761F6C0A15C
                SHA1:F4F6A1E78B790730293845FE53CE7B358C884096
                SHA-256:E3CE9D8C46937CB4B0116E8AA5649C2FA873796CF9708727499C8D746BF164C2
                SHA-512:985B3443AEAE2FCDD09C24D16728DA3F147E5940A601B206F054235176BD877553E5CC4537E8039072AE47925819C092604268B86422B86C4290FCC1FFE8A020
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):49152
                Entropy (8bit):1.6298660750702514
                Encrypted:false
                SSDEEP:
                MD5:E9FA10A0E73418C85EA80D2C215C5A68
                SHA1:E1C0A304A859FFC0278062B3384A600F753AF4DF
                SHA-256:0254C404563BBD71DA3ED68A17D446113FA2F063F33B3786931C8D6CAFB1B05B
                SHA-512:4CB60C0C18EED12E9FBA71094310441A972B97B533ED8C5C309D6599AFBE10EC13EB0EE07BF2DEC7BAF9CFCC649296F9B6C4219F1CB60140E0457C95A4044640
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):32768
                Entropy (8bit):0.06976155043202728
                Encrypted:false
                SSDEEP:
                MD5:96612326E12B99D28281B04CDB7410C8
                SHA1:BD4826BD17A801BC6D8B10496E75F1681CFA2FEA
                SHA-256:17E07268FD144BEB7C76EE8AD94C23D3441BE60FBF6963697C34AB95B0EBA135
                SHA-512:F73F966CFFB7F3E05D2FA8F517920F2AF0358C089AEDEF19DAF1F75F263FD9ACFCE0524EF96590A9F50EEA1B085C1A98914EC692A34CD31029234E5FDB2621F5
                Malicious:false
                Reputation:unknown
                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):512
                Entropy (8bit):0.0
                Encrypted:false
                SSDEEP:
                MD5:BF619EAC0CDF3F68D496EA9344137E8B
                SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                Malicious:false
                Reputation:unknown
                Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):36864
                Entropy (8bit):1.508224115945275
                Encrypted:false
                SSDEEP:
                MD5:48C24C4894F55ED79548CC9806053B9F
                SHA1:834814F10B48592A412FECD8AA90818B4E850ADC
                SHA-256:5BF0E1E46E531456659F8BC4C67C6423CD43C80B5F19353FBD562605D86C48BE
                SHA-512:35550E0C69D8EB1FA70BFAB10329A88D3D0D4EA501AAFE1BB93A71ACA0881D7F24E207B57316617353F52DA598AC55B1CE30CDF5D3AEC5D4EC448B250D19D347
                Malicious:false
                Reputation:unknown
                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):65536
                Entropy (8bit):2.0395235356887644
                Encrypted:false
                SSDEEP:
                MD5:B3325CD9C565846C782CC6DD20314D09
                SHA1:0E56CDB79398EBF63CC8FDDFB79E1A0CA412E977
                SHA-256:B33DC5DBBCAB9601763F8FEFAF8EAF342480FE86C4BA21F9689281B15B71C174
                SHA-512:C4E2D0BA20E137B70589A82CD991DE016645EBE913E4E4771569B17AAE9C396E9D8F05DAE295C9196CE6678E14B4935BFE6B63752F9BE6C0FB8072068B3EA486
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):81920
                Entropy (8bit):1.1894719475005602
                Encrypted:false
                SSDEEP:
                MD5:782D0936CEA8C9C6585D8956932F7374
                SHA1:3837B9E81FB527C2FB7E973683F87EDA6733B01A
                SHA-256:F794C9EC4F29A83C219CFB1CE0BD6AB34698B14A413CC92517185E8E77E3CE99
                SHA-512:46A0B11643FEDA5968AF9DBE97CF65977E0BF67C3109ECD659D8B2235308B683E9BA8493FB197719E19B7235EAB359BCE5A2121DC762ED0B747059FF13CEC1E5
                Malicious:false
                Reputation:unknown
                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):20480
                Entropy (8bit):1.576957073975119
                Encrypted:false
                SSDEEP:
                MD5:83D75F2C41A7A769AF910DA1172AF6A9
                SHA1:893B59E18171AA5724241DC8CCB3388C0F8A097F
                SHA-256:AE8B783FC23FCB223DE5C00AA7628BB5A1CC1DA4E6020CD6C0CD197CCAB36729
                SHA-512:80DA1F549A626ED1659B85F19D7944825C7B5C7C2B296FBE4A58E2DBCBD918C3F909CB9080905AF719D7AF843C9D954F1A0C2B80FF9EF6710ADCDED3FC258D5F
                Malicious:false
                Reputation:unknown
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\SysWOW64\netsh.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):44
                Entropy (8bit):4.073210744553412
                Encrypted:false
                SSDEEP:
                MD5:656D246C6CE9A47F07EC793B6BB27F07
                SHA1:0C098838274F64DBB02500A68B855E6703DDDAF1
                SHA-256:77429FFF9C65F96BC190C4C14916423F0196A2A570970A095285364743172AF4
                SHA-512:9E47C89948CF63770F5E59B793B8625364C9F9B679B80B9CD821ABC9866C0BC23608AEEE9794AC45E547FF11BBD47DA7BDA640D72218507EE2FA9382A9419476
                Malicious:false
                Reputation:unknown
                Preview:..No rules match the specified criteria.....
                File type:PE32 executable (GUI) Intel 80386, for MS Windows
                Entropy (8bit):7.995416882704876
                TrID:
                • Win32 Executable (generic) a (10002005/4) 99.96%
                • Generic Win/DOS Executable (2004/3) 0.02%
                • DOS Executable Generic (2002/1) 0.02%
                • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                File name:Resa Launcher Install.exe
                File size:19'256'760 bytes
                MD5:0f675d8a82d7e2d9198d1308bcfc2918
                SHA1:c284c27bcee5f0b8b978451f7db76f61ca6748eb
                SHA256:d78698c0ca1ed1aaae2c7fe878cc3d88133f0b7fa2a2430254a9ce44c3ba1949
                SHA512:4cb352e11d8f4ee9ffdaeb75e8f377c39cd7ce82d781f38a01c86b5ec8a96f9cb19b79a606637e2f7a2833af84bea3bd21a7e1daddaddf8f2495b336c4b0894f
                SSDEEP:393216:H2hvuGZfr8bwN3SLav40ml7i5IbYjvlZsZ5teX4:Wv5LN5ms55NZ34
                TLSH:22173390A3FA80A4F8B73BB12E795669063FBD615B75D4DB8308051E8E727D0AC74327
                File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........ew..............|.......|.......|........t.......b..............|.......V.......|......Rich............................PE..L..
                Icon Hash:3e5bec56762e350b
                Entrypoint:0x422c58
                Entrypoint Section:.text
                Digitally signed:true
                Imagebase:0x400000
                Subsystem:windows gui
                Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
                DLL Characteristics:TERMINAL_SERVER_AWARE
                Time Stamp:0x62E46D6B [Fri Jul 29 23:29:47 2022 UTC]
                TLS Callbacks:
                CLR (.Net) Version:
                OS Version Major:5
                OS Version Minor:0
                File Version Major:5
                File Version Minor:0
                Subsystem Version Major:5
                Subsystem Version Minor:0
                Import Hash:b48671fed9d5ca4906417d42fcdb066b
                Signature Valid:true
                Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
                Signature Validation Error:The operation completed successfully
                Error Number:0
                Not Before, Not After
                • 24/01/2024 01:00:00 24/01/2025 00:59:59
                Subject Chain
                • CN=Wayne Regional Educational Service Agency, O=Wayne Regional Educational Service Agency, L=Wayne, S=Michigan, C=US
                Version:3
                Thumbprint MD5:36F748804F5A743F035FE4B1AA23A49B
                Thumbprint SHA-1:3BAE0DE2F7B626409FE864AB57AD522E0C6A1C3B
                Thumbprint SHA-256:0E3176DBE92C6E19AF318705C307B8A0E01690549EC1BE5B72DB1DB873F027F5
                Serial:01B58B4815DB021609F43354AB97BA78
                Instruction
                call 00007F46514A3039h
                jmp 00007F465149E76Dh
                mov edi, edi
                push ebp
                mov ebp, esp
                sub esp, 00000328h
                mov dword ptr [0043E4B8h], eax
                mov dword ptr [0043E4B4h], ecx
                mov dword ptr [0043E4B0h], edx
                mov dword ptr [0043E4ACh], ebx
                mov dword ptr [0043E4A8h], esi
                mov dword ptr [0043E4A4h], edi
                mov word ptr [0043E4D0h], ss
                mov word ptr [0043E4C4h], cs
                mov word ptr [0043E4A0h], ds
                mov word ptr [0043E49Ch], es
                mov word ptr [0043E498h], fs
                mov word ptr [0043E494h], gs
                pushfd
                pop dword ptr [0043E4C8h]
                mov eax, dword ptr [ebp+00h]
                mov dword ptr [0043E4BCh], eax
                mov eax, dword ptr [ebp+04h]
                mov dword ptr [0043E4C0h], eax
                lea eax, dword ptr [ebp+08h]
                mov dword ptr [0043E4CCh], eax
                mov eax, dword ptr [ebp-00000320h]
                mov dword ptr [0043E408h], 00010001h
                mov eax, dword ptr [0043E4C0h]
                mov dword ptr [0043E3BCh], eax
                mov dword ptr [0043E3B0h], C0000409h
                mov dword ptr [0043E3B4h], 00000001h
                mov eax, dword ptr [0043C024h]
                mov dword ptr [ebp-00000328h], eax
                mov eax, dword ptr [0043C028h]
                mov dword ptr [ebp-00000324h], eax
                call dword ptr [000000BCh]
                Programming Language:
                • [C++] VS2008 SP1 build 30729
                • [ASM] VS2008 SP1 build 30729
                • [ C ] VS2008 SP1 build 30729
                • [ C ] VS2005 build 50727
                • [IMP] VS2005 build 50727
                • [RES] VS2008 build 21022
                • [LNK] VS2008 SP1 build 30729
                NameVirtual AddressVirtual Size Is in Section
                IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IMPORT0x3a5d80xa0.rdata
                IMAGE_DIRECTORY_ENTRY_RESOURCE0x450000x1aba0.rsrc
                IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                IMAGE_DIRECTORY_ENTRY_SECURITY0x125ad680x2850
                IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x352000x40.rdata
                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IAT0x320000x284.rdata
                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                .text0x10000x302ed0x304002038b7d87842b64c67b899ba5e78dc0dFalse0.5152303270725389data6.494109860999288IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                .rdata0x320000x93e80x94009065fae2bc62d08ab84e542ac170dd32False0.34588788006756754data4.655429443140589IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                .data0x3c0000x84000x24003b1c2c3bd274b21289a8012d58d091b2False0.2587890625data4.215578104820278IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                .rsrc0x450000x1aba00x1ac00bf1e463adbdd2c91a8e4ae558e65e78fFalse0.09867844626168225data3.8678528068197666IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                NameRVASizeTypeLanguageCountryZLIB Complexity
                RT_ICON0x45d140xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsEnglishUnited States0.35261194029850745
                RT_ICON0x46bbc0x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsEnglishUnited States0.36236462093862815
                RT_ICON0x474640x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsEnglishUnited States0.3302023121387283
                RT_ICON0x479cc0x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.27842323651452283
                RT_ICON0x49f740x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.3557692307692308
                RT_ICON0x4b01c0x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.4512411347517731
                RT_DIALOG0x4b4840x1d8data0.5720338983050848
                RT_DIALOG0x4b65c0x1bedata0.5605381165919282
                RT_DIALOG0x4b81c0x54data0.7619047619047619
                RT_STRING0x4b8700x4a4dataArabicSaudi Arabia0.28703703703703703
                RT_STRING0x4bd140x4a4dataCatalanSpain0.28703703703703703
                RT_STRING0x4c1b80x4a4dataChineseTaiwan0.28703703703703703
                RT_STRING0x4c65c0x4a4dataCzechCzech Republic0.28703703703703703
                RT_STRING0x4cb000x4a4dataDanishDenmark0.28703703703703703
                RT_STRING0x4cfa40x4a4dataGermanGermany0.28703703703703703
                RT_STRING0x4d4480x4a4dataGreekGreece0.28703703703703703
                RT_STRING0x4d8ec0x4a4dataEnglishUnited States0.28703703703703703
                RT_STRING0x4dd900x4a4dataFinnishFinland0.28703703703703703
                RT_STRING0x4e2340x4a4dataFrenchFrance0.28703703703703703
                RT_STRING0x4e6d80x4a4dataHebrewIsrael0.28703703703703703
                RT_STRING0x4eb7c0x4a4dataHungarianHungary0.28703703703703703
                RT_STRING0x4f0200x4a4dataItalianItaly0.28703703703703703
                RT_STRING0x4f4c40x4a4dataJapaneseJapan0.28703703703703703
                RT_STRING0x4f9680x4a4dataKoreanNorth Korea0.28703703703703703
                RT_STRING0x4f9680x4a4dataKoreanSouth Korea0.28703703703703703
                RT_STRING0x4fe0c0x4a4dataDutchNetherlands0.28703703703703703
                RT_STRING0x502b00x4a4dataNorwegianNorway0.28703703703703703
                RT_STRING0x507540x4a4dataPolishPoland0.28703703703703703
                RT_STRING0x50bf80x4a4dataPortugueseBrazil0.28703703703703703
                RT_STRING0x5109c0x4a4dataRomanianRomania0.28703703703703703
                RT_STRING0x515400x4a4dataRussianRussia0.28703703703703703
                RT_STRING0x519e40x4a4dataCroatianCroatia0.28703703703703703
                RT_STRING0x51e880x4a4dataSlovakSlovakia0.28703703703703703
                RT_STRING0x5232c0x4a4dataSwedishSweden0.28703703703703703
                RT_STRING0x527d00x4a4dataThaiThailand0.28703703703703703
                RT_STRING0x52c740x4a4dataTurkishTurkey0.28703703703703703
                RT_STRING0x531180x4a4dataSlovenianSlovenia0.28703703703703703
                RT_STRING0x535bc0x4a4dataEstonianEstonia0.28703703703703703
                RT_STRING0x53a600x4a4dataLatvianLativa0.28703703703703703
                RT_STRING0x53f040x4a4dataLithuanianLithuania0.28703703703703703
                RT_STRING0x543a80x4a4dataVietnameseVietnam0.28703703703703703
                RT_STRING0x5484c0x4a4dataBasqueFrance0.28703703703703703
                RT_STRING0x5484c0x4a4dataBasqueSpain0.28703703703703703
                RT_STRING0x54cf00x4a4dataChineseChina0.28703703703703703
                RT_STRING0x551940x4a4dataPortuguesePortugal0.28703703703703703
                RT_STRING0x556380x4a4data0.28703703703703703
                RT_STRING0x55adc0x2f2dataArabicSaudi Arabia0.42572944297082227
                RT_STRING0x55dd00x2f2dataCatalanSpain0.42572944297082227
                RT_STRING0x560c40x2f2dataChineseTaiwan0.42572944297082227
                RT_STRING0x563b80x2f2dataCzechCzech Republic0.42572944297082227
                RT_STRING0x566ac0x2f2dataDanishDenmark0.42572944297082227
                RT_STRING0x569a00x2f2dataGermanGermany0.42572944297082227
                RT_STRING0x56c940x2f2dataGreekGreece0.42572944297082227
                RT_STRING0x56f880x2f2dataEnglishUnited States0.42572944297082227
                RT_STRING0x5727c0x2f2dataFinnishFinland0.42572944297082227
                RT_STRING0x575700x2f2dataFrenchFrance0.42572944297082227
                RT_STRING0x578640x2f2dataHebrewIsrael0.42572944297082227
                RT_STRING0x57b580x2f2dataHungarianHungary0.42572944297082227
                RT_STRING0x57e4c0x2f2dataItalianItaly0.42572944297082227
                RT_STRING0x581400x2f2dataJapaneseJapan0.42572944297082227
                RT_STRING0x584340x2f2dataKoreanNorth Korea0.42572944297082227
                RT_STRING0x584340x2f2dataKoreanSouth Korea0.42572944297082227
                RT_STRING0x587280x2f2dataDutchNetherlands0.42572944297082227
                RT_STRING0x58a1c0x2f2dataNorwegianNorway0.42572944297082227
                RT_STRING0x58d100x2f2dataPolishPoland0.42572944297082227
                RT_STRING0x590040x2f2dataPortugueseBrazil0.42572944297082227
                RT_STRING0x592f80x2f2dataRomanianRomania0.42572944297082227
                RT_STRING0x595ec0x2f2dataRussianRussia0.42572944297082227
                RT_STRING0x598e00x2f2dataCroatianCroatia0.42572944297082227
                RT_STRING0x59bd40x2f2dataSlovakSlovakia0.42572944297082227
                RT_STRING0x59ec80x2f2dataSwedishSweden0.42572944297082227
                RT_STRING0x5a1bc0x2f2dataThaiThailand0.42572944297082227
                RT_STRING0x5a4b00x2f2dataTurkishTurkey0.42572944297082227
                RT_STRING0x5a7a40x2f2dataSlovenianSlovenia0.42572944297082227
                RT_STRING0x5aa980x2f2dataEstonianEstonia0.42572944297082227
                RT_STRING0x5ad8c0x2f2dataLatvianLativa0.42572944297082227
                RT_STRING0x5b0800x2f2dataLithuanianLithuania0.42572944297082227
                RT_STRING0x5b3740x2f2dataVietnameseVietnam0.42572944297082227
                RT_STRING0x5b6680x2f2dataBasqueFrance0.42572944297082227
                RT_STRING0x5b6680x2f2dataBasqueSpain0.42572944297082227
                RT_STRING0x5b95c0x2f2dataChineseChina0.42572944297082227
                RT_STRING0x5bc500x2f2dataPortuguesePortugal0.42572944297082227
                RT_STRING0x5bf440x2f2data0.42572944297082227
                RT_STRING0x5c2380x106dataArabicSaudi Arabia0.5076335877862596
                RT_STRING0x5c3400x106dataCatalanSpain0.5076335877862596
                RT_STRING0x5c4480x106dataChineseTaiwan0.5076335877862596
                RT_STRING0x5c5500x106dataCzechCzech Republic0.5076335877862596
                RT_STRING0x5c6580x106dataDanishDenmark0.5076335877862596
                RT_STRING0x5c7600x106dataGermanGermany0.5076335877862596
                RT_STRING0x5c8680x106dataGreekGreece0.5076335877862596
                RT_STRING0x5c9700x106dataEnglishUnited States0.5076335877862596
                RT_STRING0x5ca780x106dataFinnishFinland0.5076335877862596
                RT_STRING0x5cb800x106dataFrenchFrance0.5076335877862596
                RT_STRING0x5cc880x106dataHebrewIsrael0.5076335877862596
                RT_STRING0x5cd900x106dataHungarianHungary0.5076335877862596
                RT_STRING0x5ce980x106dataItalianItaly0.5076335877862596
                RT_STRING0x5cfa00x106dataJapaneseJapan0.5076335877862596
                RT_STRING0x5d0a80x106dataKoreanNorth Korea0.5076335877862596
                RT_STRING0x5d0a80x106dataKoreanSouth Korea0.5076335877862596
                RT_STRING0x5d1b00x106dataDutchNetherlands0.5076335877862596
                RT_STRING0x5d2b80x106dataNorwegianNorway0.5076335877862596
                RT_STRING0x5d3c00x106dataPolishPoland0.5076335877862596
                RT_STRING0x5d4c80x106dataPortugueseBrazil0.5076335877862596
                RT_STRING0x5d5d00x106dataRomanianRomania0.5076335877862596
                RT_STRING0x5d6d80x106dataRussianRussia0.5076335877862596
                RT_STRING0x5d7e00x106dataCroatianCroatia0.5076335877862596
                RT_STRING0x5d8e80x106dataSlovakSlovakia0.5076335877862596
                RT_STRING0x5d9f00x106dataSwedishSweden0.5076335877862596
                RT_STRING0x5daf80x106dataThaiThailand0.5076335877862596
                RT_STRING0x5dc000x106dataTurkishTurkey0.5076335877862596
                RT_STRING0x5dd080x106dataSlovenianSlovenia0.5076335877862596
                RT_STRING0x5de100x106dataEstonianEstonia0.5076335877862596
                RT_STRING0x5df180x106dataLatvianLativa0.5076335877862596
                RT_STRING0x5e0200x106dataLithuanianLithuania0.5076335877862596
                RT_STRING0x5e1280x106dataVietnameseVietnam0.5076335877862596
                RT_STRING0x5e2300x106dataBasqueFrance0.5076335877862596
                RT_STRING0x5e2300x106dataBasqueSpain0.5076335877862596
                RT_STRING0x5e3380x106dataChineseChina0.5076335877862596
                RT_STRING0x5e4400x106dataPortuguesePortugal0.5076335877862596
                RT_STRING0x5e5480x106data0.5076335877862596
                RT_GROUP_ICON0x5e6500x5adataEnglishUnited States0.7
                RT_VERSION0x5e6ac0x1084dataEnglishUnited States0.1000473036896878
                RT_MANIFEST0x5f7300x470XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.4507042253521127
                DLLImport
                KERNEL32.dllGetLastError, ResetEvent, CreateEventW, CloseHandle, MultiByteToWideChar, WideCharToMultiByte, FreeLibrary, LoadLibraryW, GetModuleFileNameW, FormatMessageW, LocalFree, GetWindowsDirectoryW, CreateFileW, SetFileTime, SetFileAttributesW, RemoveDirectoryW, CreateDirectoryW, GetFileInformationByHandle, DeleteFileW, GetShortPathNameW, GetFullPathNameW, lstrlenW, GetCurrentDirectoryW, GetTempFileNameW, FindClose, FindFirstFileW, FindNextFileW, GetFileSize, SetFilePointer, ReadFile, WriteFile, SetEndOfFile, DeleteCriticalSection, GetStdHandle, EnterCriticalSection, LeaveCriticalSection, WaitForMultipleObjects, GetCurrentProcessId, InitializeCriticalSection, QueryPerformanceCounter, GetTickCount, Sleep, LocalAlloc, GetProcAddress, SetCurrentDirectoryW, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, SetThreadUILanguage, SetThreadLocale, GetVersion, GetCommandLineW, CreateProcessW, GetExitCodeProcess, FlushFileBuffers, CreateFileA, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, LCMapStringW, LCMapStringA, GetStringTypeW, GetStringTypeA, GetConsoleMode, GetConsoleCP, GetLocaleInfoA, IsValidCodePage, GetOEMCP, RaiseException, GetACP, GetCPInfo, LoadLibraryA, RtlUnwind, InitializeCriticalSectionAndSpinCount, GetSystemTimeAsFileTime, WaitForSingleObject, SetEvent, GetVersionExW, VirtualAlloc, GetCurrentThreadId, VirtualFree, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, HeapSize, InterlockedDecrement, SetLastError, InterlockedIncrement, TlsFree, TlsSetValue, TlsAlloc, HeapFree, HeapAlloc, ExitThread, CreateThread, HeapReAlloc, GetCommandLineA, GetStartupInfoA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapCreate, GetModuleHandleW, ExitProcess, GetModuleFileNameA, TlsGetValue
                USER32.dllSetForegroundWindow, CharUpperW, GetWindowRect, DestroyWindow, RegisterWindowMessageW, AdjustWindowRect, LoadImageW, LoadIconW, KillTimer, SetTimer, EndDialog, IsDlgButtonChecked, SetDlgItemTextW, GetDlgItem, SetWindowTextW, GetWindowTextW, GetWindowTextLengthW, LoadStringW, DialogBoxParamW, CreateDialogParamW, SystemParametersInfoW, PeekMessageW, GetDesktopWindow, MessageBoxW, SendMessageW, GetWindowLongW, SetWindowLongW, ShowWindow, MoveWindow, PostMessageW
                GDI32.dllGetObjectW
                ADVAPI32.dllRegSetValueExW, RegCreateKeyExW, RegCloseKey
                SHELL32.dllSHGetFolderPathW, ShellExecuteExW
                ole32.dllCoInitializeEx, CoInitialize, CoCreateInstance
                OLEAUT32.dllSysAllocStringLen, SysFreeString, VariantClear, SysAllocString
                Language of compilation systemCountry where language is spokenMap
                EnglishUnited States
                ArabicSaudi Arabia
                CatalanSpain
                ChineseTaiwan
                CzechCzech Republic
                DanishDenmark
                GermanGermany
                GreekGreece
                FinnishFinland
                FrenchFrance
                HebrewIsrael
                HungarianHungary
                ItalianItaly
                JapaneseJapan
                KoreanNorth Korea
                KoreanSouth Korea
                DutchNetherlands
                NorwegianNorway
                PolishPoland
                PortugueseBrazil
                RomanianRomania
                RussianRussia
                CroatianCroatia
                SlovakSlovakia
                SwedishSweden
                ThaiThailand
                TurkishTurkey
                SlovenianSlovenia
                EstonianEstonia
                LatvianLativa
                LithuanianLithuania
                VietnameseVietnam
                ChineseChina
                PortuguesePortugal